dhi.io/cloudnative-pg
1.27-debian-fips, 1.27-debian13-fips, 1.27-fips, 1.27.4-debian-fips, 1.27.4-debian13-fips, 1.27.4-fips
sha256:d4936439e86ba7f4abf3296e68ca89ab6ac7899d496a8034c2d54e89d80559b3
Manifest digest:sha256:24bf585eda4792762a0923038563c2270a32b3d15db2c511c4701e3501e80859
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:d11df8026703f4c1d2de02379a88986b2678721f7ff0d57f43c8a69db47fc719 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:43406b059f50430002f24617878d17c4a44526468520459e08ccd225624fb484 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/cloudnative-pg@sha256:1e60fda34b361d903c60c04b13143435a933a075c557e2a4d5a7fd9126f94423 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:21da183b86a8e4039eb84501b45335388c1027111547f94f098491425ca11406 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/cloudnative-pg@sha256:17055051b5dd28a35b61171e287328384ad92dfb2649d563ed7857e2b94710a4 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:73736a59694b089bb09f66c11cfb01ce9d6b588f7ffc9db1d49d4052b09e9823 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:94a423bfef6f82ef501f516bf60538940d0526708611e1b2a18f3604ea32d64c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:b6affcef343090e312a1d6de49f6a1cbd3911f10b412c8df83e61e5440a9ba4b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:12d5fa6bfa69226805bfe1f17cdb7a6ac3e99281bf8cffdd215e875aedd88a50 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:1b27acb680196a1e3ecfdc0c62ed32ff7f66d67b3e74482ccfa880f81f00dc2d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:de71737f17316441d600f3bc08a722cf02ed8a1ece87ef2033d81c75d7f6a467 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:c3c8d54b1d4a76a31a4d9f3c6f0f659bbda7e8e5752e6829ce2c4c1d52682655 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:416d1c7f8ac8f3ac9f62d41cfa26b0ce463d9a4c582330ecf3f87ca4fc28a8a3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:9ea4514489e90014abb2c3ab42eb804d10aa96e7ed6a792d8b5d35badab55109 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:63497d1e81e8c36104461f12066e861e0426e640be86b8298e3f616976495856 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:7a3690fa1a7e4dcde59a2ceb0ff59bd917f93d6e16b896615c47de0b510ad42c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:bf407e079f3f35f4362beb2502343b91b3a5d8c9f051cd129e6348a6424cebee |