dhi.io/cloudnative-pg
1.28-debian-dev, 1.28-debian13-dev, 1.28-dev, 1.28.4-debian-dev, 1.28.4-debian13-dev, 1.28.4-dev
sha256:3f1c3afcc756e6dde4065270f775ef0c34ee6747c0cb829b5a1495b4896fcbed
Manifest digest:sha256:0b05de22ae0a7a219f1b078501b987e38e9b40d91eb334d65abc68d840180baf
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.28-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.28-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:056e66befb8bdcfabf9b12f81daba444935825a94285afe849994d8b3e237c8a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:d4b91d5c1454cac7a8f9b2371c46b46ab7f874820751312104ef4fdda2a0e1f5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:9dcf1fe453caec69fefaa72b28b75f0b0881082be03fd38bf99ac09f2076e5bf |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:fd79897346a0ad769f5301754dd04d87f031164a1326ee0fe85673a103c4fa0b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:462922d3d9491761d863b7b9468fcaffd974ae97701e1360c3cb7b1867fbcca8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:d4f3a56b3d2e1b4fa26b7a12943b53b18b4e28ba7302a503b491ba215003a6ac |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:fd2ad30a3c55b19857e1c877d1365669749135a5a95d085b913d5d530f462391 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:19de8385d8a38ecdd3085bc9886f3de8ead0a4a2d76e052c26ecd3e2f9eaaf28 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:ae86862f1e2b5f507648514a729a9b80820b04b5ce35962ce7f59d88dea5966a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:faf74cde4b52265d6e4d84d7cc055a4810f6ec0ae7ea6ba2ad2478ab57bb8f6c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:80061e2412d3da3b33c5a9622ed61e437cfcbfb6ff24e837fe41bfdab383ffed |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:8595d6674689bd4302745f7950a7714ed9b5ed1ee4e244f8fc01ba4cf94e8d2f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:94373d0b32010f0a0f66223bdb2f7c3647943d5bd58ce0f7eb2bdff268d301d6 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:4eb23c9f6aae62971b0cd3ded286410a24c5e0ed925635b040f40eaaf7ef9fd9 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:45a6da4b9f100eae389ca0465ec55bd6b90bc7465bfe23f673c3b38a629597c3 |