dhi.io/cloudnative-pg
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.30-debian-fips-dev, 1.30-debian13-fips-dev, 1.30-fips-dev, 1.30.1-debian-fips-dev, 1.30.1-debian13-fips-dev, 1.30.1-fips-dev
sha256:5665372191e63df362970f20d2f1fbae1fc62f1b3528937f6e3a10b745c03a0e
Manifest digest:sha256:7559306d51d163f0b1927f80c600f3db4d5b86ea557b0093ecbb3dbe79b3d243
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:c1fdf570da8e095dd50358976d9faffc12f5910ca23fb79ee4843603bb19a4aa |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:9b3c15f894190d1dc3c5d40477d3e18cb2a8000b6667efa04b2718fc2329e421 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/cloudnative-pg@sha256:794dee9357f6e38c9d8a5e0078a2a4de80c397a107fac27d570396de85b409f3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:179103a7544a1b4ece48abe92c15a574e2a7649c0ab803b59904cb2a1bf8f926 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/cloudnative-pg@sha256:73bc3aa2c9a6cb3432d637f8b74ed0e7c1fcaac1d627add1691899781e5d31b2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:f8551d55efc6b61a3b86a83e41c4f2cac436868eb6212a0ccf3c37c667f3264f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:04fc99563dc7ff278e0aeece4c1b99c14c0981e5efaedf8d351eba5fc53dfb1a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:16b88447403d9b78979b7fe92a3f571be7e9e49d315cdd557deb3a80226ef41c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:7cfc599694fe65c721dcac01355a1685fa93df57f0a8c36a50bb7dfd6def3e0b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:e105b43342c5d17432d6c30476f1073790d5701081610f1e33db1076449b92a2 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:3432b104ad48152c9ca224b7fb05d452cdb83cbc6135fb8afc06cb4848c42c78 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:31f63db268442fd50523183c230f3f7b949ee8ea595185f7ca17dd35d8b01bb8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:4795c8c6e3a92398dd5609b2ff1c7c96b4db35cf4ec02e9868749a5c85f54aae |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:f889d556ebfe947c3fd3792194cdca3b85bed237cb986086561d4892918b08b9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:83ccbf4347d23c706722cb38357aefaac11fac74f061c1bac4248871a740025a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:0ece1ee4a1a6ff808f62fc19c803f6a01d8620df7c3a60e121a527b9ee8de712 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:aab1256d120b0af13367b837ab6a8cb925fa3ddaf09bc158f7738575e3331344 |