dhi.io/cloudnative-pg
1-debian-fips, 1-debian13-fips, 1-fips, 1.30-debian-fips, 1.30-debian13-fips, 1.30-fips, 1.30.0-debian-fips, 1.30.0-debian13-fips, 1.30.0-fips
sha256:48b7520dca7cb9126d0e107246420f1018a124aadcc75f7837608d1ad1c8ef09
Manifest digest:sha256:7915648c2924905ae6a5e67767a70b843bb98a19e02d0ee60004f042cffc7985
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloudnative-pg:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloudnative-pg:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloudnative-pg@sha256:e64e257724627ee207c877f46d2898d876db7ca7c5a042e431954620080e287f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloudnative-pg@sha256:f36ae91116a997b8972e8e3a85a212cdd68706588b079a1e073127ea4a864801 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/cloudnative-pg@sha256:6fceae4ece335d484848ece50028281b632eb4fd05e193ac5bf28f016510e625 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloudnative-pg@sha256:36aec46b28c68b3606248ad2fb80c865a52832151a556bdcaa12f6427ef66b94 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/cloudnative-pg@sha256:01376fb5fa703261cf0085c62014955b163b3ebe927755c0ad4f8423d464048b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloudnative-pg@sha256:8a97c82111326417e150da45aae8404f9458bca6d15d77cbb599c8edab71d01a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloudnative-pg@sha256:6b0f54954413d0afa52cb1c153b20a2610b65ca72c228450a198fe66eb7fd29c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloudnative-pg@sha256:9407e10e6e970156dd78bef24bdf2fb818a281d76fc4e0fd719fe04b6a8b621e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloudnative-pg@sha256:89a75fb4383d8ffdfe52dfeb9cbabc4e5e7f932f57699d8cccedbd275f64c271 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloudnative-pg@sha256:014bf419f543e21d092a201b4cd2ed8bffb94a8c36a581b6cf88ea6f71b9e1e8 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloudnative-pg@sha256:00184390294b5d326a6547569e5e187d58c8b2e5f8431154e91ad173d6bbfb1e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloudnative-pg@sha256:6ef468f213da8ed637e838e67f2b36bb91b619164275ee5fe3fc697c27a08a77 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloudnative-pg@sha256:6ee2a5f286b5745b81d50ef00db6142086ace586deac7b8bb0b4c8f6f2162fff |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloudnative-pg@sha256:b01988f539ebce263a88bcc902e89143097111cfbf9b5b56a479dee1f6a2429f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloudnative-pg@sha256:e4fedabeab3ab04b4824d1b0a1b23a8cc7106cb09a08d4abf82b0d0f1dc65e8b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloudnative-pg@sha256:4189974de4334abeda9d9a96c3781ca6e83cf6d0c7900342f01fec15335fc569 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloudnative-pg@sha256:c98b096b4719dee7cd213d1933f07f9a376a169a988987a166334d97b2f4ebad |