Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.27.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.27-debian-dev, 1.27-debian13-dev, 1.27-dev, 1.27.4-debian-dev, 1.27.4-debian13-dev, 1.27.4-dev

Index digest:

sha256:b2e17210163eba63b1c18f3b941a9d19a28f99d036cade50889dbd7d2fae577a

Manifest digest:

sha256:7d7064f7aa393f7770cdba19ef412d08fa019b9e99f119875cf4a591069da1c5

Size

84.14 MB

Last pushed

1 day ago

Vulnerabilities

1
0
0
1
0

Support

Ends Mar 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.27-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.27-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:38dfc9c09c5c0092f83b84d644e0bb126cd21112d910e2ec277bd358fe95a086
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:bea1e9eb60034a46cb538232ed3f39124cbb7b018aec0603f5a166e26615bfea
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:0436fcad8785721a35206de00353be290538c86da68697cb3ce6e99d2516c427
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:c18650fd64bf28368fd553cbb977348474558f2365a72a5eb441a6a12343bac4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:048a2e1324a31bc05a584dea82b5422ce01eec5717d27c451ea17814a2d1cd84
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:958ed8e2d62b2ffea725610abe9640db12dee3a5b2724587c23ba497c031c08b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:ff7b320d142f3caef2303115b90ba6c5c96b48f097a5344be1cd29b4aac364ff
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:9a923ee5f5ce4680e989bf7da5a05787cb9200535db8b6483fd493a408eb272f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:ab9b8a9d6a147bbe12655f02b7a7244e95a24b49ccc7f76141d273e9385ffe4a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:80d7a93acab6730e1d3fdc8de09c4f0d6d442e6477a94be6b34ce7db80b1da41
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:8b31d3478f1fd7f33e8d8ab3554492130ede57e5d524bb4e4d182b4818308a07
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:ffa440e3e1510f0eb8479ff91e7a05fe55a1d030410bd01ac4b3aab427bd5fa5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:cdb5be26c88a9a7c51b7137c8f285f988f807529be3d6f647878b0245b25a0a2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:cb04a12609abf074505f1a0578b9216f03585ac2a97e19521176ffee6b1f9b66
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:c4ac756ee78fdf86c80920285088a1914dacbbd3f1cb6e4ce1c8bba8ca8ad7e3