dhi.io/cloudnative-pg
1-debian-dev, 1-debian13-dev, 1-dev, 1.30-debian-dev, 1.30-debian13-dev, 1.30-dev, 1.30.1-debian-dev, 1.30.1-debian13-dev, 1.30.1-dev
sha256:979cc52b404f0e5d56ea3c68afbf574581dd358e18e98abfb2f7faea7eabae53
Manifest digest:sha256:5b10e2a48328dd59a666b2d98424f4fc438285fa3139c77d2c52d05428a1c52b
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:bac7b2924d98bf75f8e76d17dfddbebbcf980036fa665c386595de06796edcaf |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:c8bd31ec64ab279d4b38d090e6d148dcde73f6c74c1e426bdd80755af969b34e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:d7d791718e675fc18c03cf8fcbd4a1cf3506f2a73bf185b20f502a4f6c02e1ba |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:e8f0aad4fa7eb57605d5d6f6a21d104838e2fc1ed89aead5d04ae0a77e95b1a6 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:8e543bbe615217fee6bd4cc33faaef07396e1d219456c008c27a78a86cafd828 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:bce5a27e8473e96ff37f74d95aa928fe22d5c5ca7684e401a69886af513619d2 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:4f0301762e2842ed45451e71d714bb6c1efb5e8be409f6835ad2f7e11da61f39 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:1bb5b617e75fa0afd606a70ff426eb3cd30de4bdec547fd9f15a85bcf8eefb23 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:a9c980ad90380d47c6e60643bc94894dbe853581003c00e48b63880e16f917cf |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:efb03ea84f5c1aff1d4296a2ad35c1e0dbeb8c3fd8989baa9ca27e365fd836ec |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:7e3b301a6448362690418093072ab956e09f7cd384d5df306c7bffcd12efee0e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:f052407f22d8520f313f1b8aaf3867cf0f9d9fca0e01ba048d27c4ce8b96d500 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:f23c1e8316a355399259c26c54a1d69b5f1f586acd176c10c9d9a56dc9641c65 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:25cdd4bc0431b6fae560b173c9c0f9ab200dc94f4b0216931bf43dca41dd284b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:649a055ac04c54faacbfa9eb5d67bc85c40b71c242ed48ff06a65f2691a0d7f5 |