Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.27.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.27-debian-dev, 1.27-debian13-dev, 1.27-dev, 1.27.4-debian-dev, 1.27.4-debian13-dev, 1.27.4-dev

Index digest:

sha256:61ec3a0c92eb5f7f751e6c700e5eb6effeeb90c11b897a1def4fa81050170aac

Manifest digest:

sha256:c69ab4870c394621946c9d39bc6f8a3b291ab8279e80b218809467ad4e0e3ee9

Size

84.14 MB

Last pushed

6 hours ago

Vulnerabilities

1
0
0
1
0

Support

Ends Mar 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.27-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.27-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:d5836dc2b01261a90e86886da0ac2f8f421ff7ae35fc0b67554da714005987f8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:aac494481699b44be5798d7ac55c58098338aede61d54ae97c38baaa55173376
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:e9599960c61c017034c37cbd7548d2377048383f652a60f7d46b4fbe76faccbb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:680897aa585e70407addc027e2c842fcc89c9d886f2e29b35078c4c34b49b03b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:2c6a58857b949be4c3e27dc37ad9b298e2eba4496206294d6a3697f9eb8790ef
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:a462e2cf3764164a13edbc0666a7fd1c9844c53d96862a6c0f37b09588194835
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:ebc6c3a92ff395bd472491e422b5bfa8e2a97243e7defd850d378af775cc2dfb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:901223efc05400bfb0e069390441626572444f924212a525b353362326bff028
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:a40dc2860d4793c8c9f02539c4d0e3076183b6e162d9f1dcb6d80d72dfd1a671
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:e3eeb5d00a500d4b3a2753638d854b265da4c6a71e3c7447d576bf5d90d7f56e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:a31aa412c020e4deb298069b80debbcc51b06e39775845082d180704827159d0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:4da585ac3660d5f03bd4a6265506a88acb1aaca70ff4c7668ab5d54bc9348cfd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:fdb5f72f29dabb7776d49b45fa160e0d90badf8f04bf2045e233f9c67f37e070
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:057ab1c4d85a5168275c09de894ae2609ce6b69d94e899fc5c0be5024b9e4012
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:16739a3baf23cb72a0bb69acf30c30b52f6dc6ec53687413248c031f263a0222