dhi.io/cloudnative-pg
1.28-debian-fips, 1.28-debian13-fips, 1.28-fips, 1.28.4-debian-fips, 1.28.4-debian13-fips, 1.28.4-fips
sha256:548157d56dcd658846e8ee14b8a40a19aeb730196338f74c990241f35c060945
Manifest digest:sha256:1af797b661a4c7d5c7b30269f6ce4e68dc133c545f8bbd180bb2746990d6c805
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.28-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.28-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:37ad7270bb3d2165d089f36e5fa99c29b683876805590e75bbf0c509d74c3b80 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:86c17b9db0ad3ec30bc36945f48a2987bc3e2a039ed5367d8e333e9a3271b3f2 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/cloudnative-pg@sha256:a94640c215c68d6b14114bf12ca1210de9af61790cab518f9a0a3df5bdb33016 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:6fc687eb514a00c25f1eb77797d0e0ebba119dd4b5c68aefd28256fc287f7a3b |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/cloudnative-pg@sha256:63d50e6017edaf02ef143b27e8acea01cf1010d2674d90a2b7867901459767b1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:733c0e7137c2c1c1b3b85e7fa8aa6527725a4ffa7585a1a068bf714e3f3dfff2 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:331a136e11e30b27763f21b4435498aec1e6b1951dae34672d533a1121083bd1 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:e68396eadc59d5209eca18e01f89536cd9f95131685cb24847d854cd019b308b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:13cb22051b875a24059d66793206370090e8dbbe0708578a126f10f87d03c742 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:c236c02f26c89c53574d3eb6967670d1051c3e58172a99e6455025908ac13dc4 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:1d2b5b1480c4438e235be2fe06a100e1e30b5c87836c2599cc8515ac8bcd3332 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:b88360f4dec6d1aebe13412892df109c218a8c18f2ac51bfe702de00763101b4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:48ec30e481fe45e3bbe095ea15da60e929fcea8766fe8b64cfe5e8bd4dfc0ca0 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:f4411b7202687b67fa02a3f575afbbf53a34eabe8b77f1d9e7a9074c46b9384d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:309b6722741727cdba7998be8b67d4867aa251a6808dffb3710c3d30dc608f16 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:c7fef2a7d570200a1701d4c300276b60734574f19eb584526abc27c544e3730d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:d0ee14abdf8d7465ace762029e47729f6327f8962af6309c3bcd1e42edc4c33c |