dhi.io/cloudnative-pg
1.29, 1.29-debian, 1.29-debian13, 1.29.2, 1.29.2-debian, 1.29.2-debian13
sha256:3571cb3a0af0a67eeceb3fdf661813bc2b9a3f6b4a318a2bc6b1c00f1e3363c6
Manifest digest:sha256:982fa95a46cfceb28ce449ceab549fb7283b48897d2f81c45a871b613be6721b
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.292. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.29 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:25afb90bb96c496620c70de393b7076b1be20598a513b5876e0426f4b26482f5 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:8ae976de5823b8e5cc108c7d6e261b0df7032fca45cad81f1cffba28fc354ff7 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:c92d4ce203fe3c298e9afda4cf2cda89cd387cfabe67c23d9cf7813b03e90451 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:ca2192ee1d53d9298c77e0a1553fea4fb73b4bd3cb6fe93cdcdf8b2d0efa021e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:fb5f1582bc9b516d77d165cf99237539937ca74cded5cf9e5c84f91d83da5f88 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:7d16d4332f9fee8e8195fd990a88a3ef3a49da904412e2ac417e6b2ded904df9 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:da27be33c51ae8e50c0fb54d7189d1aeb9048883f9e97892b6705c26069f6bfb |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:99a4b9cb0f788b67137472d25a087fc22606d233b9ee67f9185de425720f9b07 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:07a601d1ca00e9153faa309fd8f5e5b342b20805c553a2d0f75809b615b22398 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:585a93b03bbb8c64cb87eaf792f7ca5cf6c5f2c1325dbe9613c74ed1627acf04 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:836bc9e9565471a0d1cabef6dd06e27303e6bb437b1b3b1aad97bc5570b7dd2f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:f1b68d123ce560cf7b4e4909494add87a234d93e782f43e2df0ec7493d86ff7e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:1610b2aaaa91907aa37e1310f6671c631c2dbc8ced126ba94e917011a0e4e0e2 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:65fa4b04c113df8398c37d2c02b6d344ef8e1fcde211e8ff2e3e6e9b26443927 |