Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.27.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.27-debian-dev, 1.27-debian13-dev, 1.27-dev, 1.27.4-debian-dev, 1.27.4-debian13-dev, 1.27.4-dev

Index digest:

sha256:bca9878072a2964418b8d2004610843998eaaa67344344cfcbd0c4576f99af39

Manifest digest:

sha256:81bf9835a2e6d4ee2ea79c9e54ebbdb232571e29d3add0936056a6aec53d19b2

Size

84.14 MB

Last pushed

1 day ago

Vulnerabilities

1
0
0
2
0

Support

Ends Mar 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.27-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.27-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:a5bb28f9bf8a8af43e9622f996d2085852e0a5c571f5bbdfea28ca2acc3d0269
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:254eee4ed3bd4aea9d1df02b1055afa795ab150dadbcbe9c777b4faa85e8136a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:bb192071da43029ad1823fbe949e6dd497a6c741f1efe91fc082090971bf357b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:2e79397175e170f1e5da370b21d7a2387ee94cf61d7d14fe416c1b3d8323a82e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:fe55bc245cde6c07aec74e37a5af0d0e51ca6357077da46ae3bad38edd14436b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:5e0680de1c50cb79379744e9696f64e177138658e9cee9082a7bc2f1291cf5ea
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:3a48444254a6d58943eff6e592ac003f93eb2ff6e1b776e4806043122238bf88
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:500a073634699e0847fe6534cc9520e748084cf984d5e82ed3c2d7ec7ac36f2c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:39c3080f411c296dee9b8135c9dcd327a89fee17c0fcdb7fed8926f0c51f80c5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:756c138b8c57bb437805e07851d349d777ebe4634decff843f773233b3a5bc1e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:da25e553eaa5328a2a02c1de433c3e6dff7c0ff22201a586db8de9427a658dae
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:9cdf3d6fc73a4c0494b2d7d14f8ea777eb2f7b5ed8303429486b2cd3fed888b3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:cf2002455f62ee3dd3559ac2f17f3ed2282693ae9ac7ecacf45edaa6c32b4016
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:a3c3a29c2bfc7efc3540cd18ee86e7f0e839a774b57b44672be1edfd8ebfbeaa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:7cef3741f274f918a3536694ce78e8d0c4ec476d0d145a3e78677db7678299cd