dhi.io/cloudnative-pg
1.27-debian-fips-dev, 1.27-debian13-fips-dev, 1.27-fips-dev, 1.27.4-debian-fips-dev, 1.27.4-debian13-fips-dev, 1.27.4-fips-dev
sha256:326e6383f5442da874b38905b20dec0447fb9c5c39334c5eb5e50108139178dd
Manifest digest:sha256:80641d24fe1f3f3eff9ea7742da8aeca314e7d47d48d430d6f21a83847c30cbe
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:d197726d25bcd03f88d5ec30570594399ec7db72aa2b4076c0367a20b808b805 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:8eb11371d3a7f2d0760d5611deba74f58ed251c23dd91fa37fe87fa72a79a045 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/cloudnative-pg@sha256:4a31b14aa43f3c5102448f4f079dd772431d1d43f533d6edded17438d4bb0741 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:24b203af7f9c730a53d348623f4557e6b33b125588db39e4f6b6f764bf69fed7 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/cloudnative-pg@sha256:a583638c888566175ee5779eb788fd95c8a8ceb504e85484bd1ed412d8dde94d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:c9473c7e439f7f2703d520a696df218b444758e2076bf399fa0e9c255ec471fd |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:89234331626c1f9b8aea6c77c18962ebe2a5851e6c5745a6009fcc8c68c00a87 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:a16d8a3155a55010b081ee3bddee7c1795699ca5abb41430f5bc767767ed6d28 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:f31bd2cf6b61bd4fd3c09c66852409ab21bfb82ca73ae1a028cb7de99767b993 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:794c3763911b68ee225c1555f6bc768c1b7b382530713d8b978dd1f2660ef750 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:6142fdf4b8d3b00bacf2fed76927fd939c474859f986552bc59e92d51d92ecd5 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:1f72a76ee3d03315ba35f285a2d05f964067615636ba552fc2a984ed9c1ad679 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:e29bd099eeee45573912bf7074a18a14fe1f187bc6cfcdc0968c154d1e5d943d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:df8c15f3cfaef41a80a7f5efaaf88dd7b23446fa7bad9b5a4d14d28f3809f625 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:8fa65f8ef8276fb8fac14841e69dd97dfdff05ccc804a16069c15f9aad235dd8 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:59c856a9e906da0ff4254860b7b32f525e1ec6ac1f221ec0fc92430dc1973a37 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:1ae5238abdd7dafe91bc3e0e6515a1b9e87176b9b2f0d21dc043e218f3b5dffb |