Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.27.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.27-debian-fips-dev, 1.27-debian13-fips-dev, 1.27-fips-dev, 1.27.4-debian-fips-dev, 1.27.4-debian13-fips-dev, 1.27.4-fips-dev

Index digest:

sha256:a55dbfacf79260d270afa3de19a3bc4da6b7dc5b603dd334356b93f37543b12e

Manifest digest:

sha256:0fd774c7852f7ce1737ad3b2e60b12c51b2c6f0b513cfda5d8cbc1f1b9c56fe0

Size

84.90 MB

Last pushed

2 days ago

Vulnerabilities

1
0
0
2
0

Support

Ends Mar 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:501f24e1e6353dd131aa0efa67f5e15c30862a54e41b8abbc06f6a49d14a1700
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:03b0680130f2ac969db204612c1bc898b1569a512418ec07d68475eafce2b72a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:473fd3b59971e963c8107a078e5c87f09db37a1d1bc73bdda929aaffb122d917
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:0e8f23ce8972936d4d14f7b666d95f1d9c20decfbc5490ecffc9b6dbe0e85858
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:6110ece789c1db6a1355a34937846304bdead45423ac1aea69cff618fa583aa6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:e12e5c367d385e8840df00af7dbe8e3b9cef2e78b3a96f9cdcad053975325b7c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:07ac826072fa43fc60ce68cf35db080e3d22dc6433630ea9edf6f0041e15e254
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:48e75b94fd4048f54e22c2a285b35322439a77e236ad4904cf3a59a252cffc3f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:43df5eca28af77f4b485caacdbe660c368ea14aec674bff9b0bee9b3d753b70a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:b0c6370c3d3ff3b33eb4bd113208c0f87e82510376ce85d940cee1b4e350fe89
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:ed774f5224f607ee55286993d1b3ddd1bec28772db93b59bd707a6d51ede2d2a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:c6e5b9e61c1cffc52ed7eb347a776d854ec0eb838cb5d666d1d1c351fd6c044a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:f098b5af2e9092c03516f3f5efd0e06dbfd01487e87b268038870b486feb3dd7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:7eec9b2c01f6661e3d468a477e2cfe534eef8ae10fcd9fdd993aaeef1d03a2d1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:d11f8bac9b739af78bd9ea01b133dd524313d1291f8db7a6b7aff51a2707cff1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:8ed9a1b81d4e462c627c6c38402257a07368f79a2138a1d25ad806ae20cd5cb1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:d6eb84555ca224abe08d9fce9f2677513c9c7dca0e4d7bfcb69ee9f801b1ce25