Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.30.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.30-debian-dev, 1.30-debian13-dev, 1.30-dev, 1.30.0-debian-dev, 1.30.0-debian13-dev, 1.30.0-dev

Index digest:

sha256:e7e94b50b7e32d06d811cfd22acd9d3c06169d4a0031b2de16199cf4f951f03d

Manifest digest:

sha256:05199577744808b5c61c2ccb38596b01db8da284c12e095d907144e3cbf56737

Size

85.37 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:2b4bd0be7d11aae3ab1180b55b193eb9aacdb964c753ee8dcf2206fa5a66970c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:32fd9d4b3706e1f1e6ccb1ee84ac7a412c51b27cda11cd4c3e0a9593ff4ca04f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:64d5c9541eeabfc0edec2b98df1abb4842e509db7a533761d7568a4ed369e89b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:13648f32e861d5a85d75b00ec24ab169f6758af703350da8bc0018f7ce38cb77
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:225a38f28c5900c2e46bd59a7392084defabe664db54877e2d845ff693ac1530
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:daa1f450b070a430ab20ec511fffbb50561bc7c22502db8b3799e674a5306386
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:6b45e0551554216f1be9908fd5a935b49ca18019458e181dc9561f8326383bfc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:d61bfec6bcb91691681b4abdfde1f8d60368e57553945446285e7d8cf0423b2d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:5f2b6f1646cf23201840378dbb45ff10586cc7a624a7f26d8db403f5ee4de2d0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:a7dd284b1627426bf17cc6efdd4cbd6839490551caf9d8462b883de9f5219eee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:4b20c084e99a37e5f796ffcf92c22eda42070cbaf041f2fbea74837211d3897a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:4f4f1805a366576f2749119f1cf6113ef71baf74e1109774b88598e55888c2dd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:6c09807e2ac0af4dc68b63315e5c264179b2d31b95853f234b3e3fe466d75403
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:82eafa3363783813e08886bf49a39b84d76788b4a9060e541ef8e7249ad79eca
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:d08cb14d23b26ab10b85b416e06c8dfcc521480580c798f7bf9ec539251af7bb