dhi.io/cloudnative-pg
1.29-debian-fips, 1.29-debian13-fips, 1.29-fips, 1.29.2-debian-fips, 1.29.2-debian13-fips, 1.29.2-fips
sha256:6a5966c48d7da4eae32dce40b95b0d9c3c86ebd2629aabb97bc6ec86b89e07f2
Manifest digest:sha256:bde9c61aec5e7fbff4e73f097333af928c351feaa98fa20024118728696921ec
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.29-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.29-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:36108994da27632d183b1a390d16429b78fbf0846989689c13a9289f96c997cf |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:c03d5cebd070b32f789320031bac8096a2ad9d623331ec8328a298425b5bb0d9 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/cloudnative-pg@sha256:45743ed544dcf4266f476536b685206e3fcfe30d583c0d29753d313bb7d60b71 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:14007ae985485138b3c21741679a9419bf33bbb41251b48df601b0a5321cbfd2 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/cloudnative-pg@sha256:4aaf51f3637e9fefde8bb983b2c829e091532f2a67cb7c2152a5b5d64f6c9d06 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:cc4f9b20bbc5fd4f1916d89fd60e0b5d047ffbf8f193e85e6313a94776d0fd54 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:1567f09e9c5946fea598471bcea43d73c13e4230ced3c29cf11d79845cf0660c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:6c0edba70cd2a18a080de365298a214278afc5e9d69a644b7df5248a8db3c2e8 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:682afaf4257c077e080224e1488aa8854daf6d6d63c30beb20cb601042c8f53f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:6236a1d32a1268bf7cbd56885f75f6f6d6faf63cabad38a88d1c284addecb9d6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:68e08886fde1a2f1663561afafe515433e4a6eb985d2db5b85b54abb7a7bb595 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:dd0bfe2dd180931014567066dd6d883ac72ea74463967312e020e14824fa6139 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:12504120360af8fa690cfb6054ce63d18ccff1fbcaeda3f52a5b6bc0c8890473 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:5fcdea2147940cdd019d1d24d9530c2a9bd5fd921070fbbef57bcc2c75a3df0e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:27ce341186270ed2e7a789a0b7f5affd6bd2aac1ec30a1bd845d41aa68ccdc4e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:4d22e017b93e522551b7d7886b214678fa98cb680de7ba7495849694c37a0099 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:5036de8338178d92dc8cdb3c931f01bb726bc5e54b34735243f1e125342981bb |