Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.27.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.27-debian-fips-dev, 1.27-debian13-fips-dev, 1.27-fips-dev, 1.27.4-debian-fips-dev, 1.27.4-debian13-fips-dev, 1.27.4-fips-dev

Index digest:

sha256:8f3b48927ce7b6067ee77fb5aa11bac9a1ced9bbc917bf6faf5b2004a872a73c

Manifest digest:

sha256:80d4d363463e79a032b88023fc4ca088fe58bb19483b0aeceb6c9954a7e78892

Size

84.91 MB

Last pushed

18 hours ago

Vulnerabilities

1
0
0
1
0

Support

Ends Mar 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:6901176fb7b405e6c3eb911e1e65a64c2e1dfbebdd1fcbcb47534ee4f8f43717
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:eeda0811a319a13946514628bacc40e9384b26592477e774995dc7e19ebd1c91
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:2414e32a6118b8ddfc5036bb47814dfa2df3bbc8ba5e45b8a0662418b20d8b0d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:eaee47ea111ff15b39dbac8b785edacbbea5691aec09607667b8131f3c27bd3d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:bbf3405f8ac046fe47836f8649d6c5d1f9597f2dbb4e6655f0c36c6ea3a42ead
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:6c0f86b1acd6d84769e8fff249d4c99a3c29d590914e2478c494346d53510f47
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:f145cc13fe9d85bac15bee67c57b4f33d3f930d371e653cff98e1be86c8f59ca
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:a610229b87f64552ee3ad0907afe640d595f9f7792cd1d156f1e22ed6f4b54db
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:9d0bd87418dd28fa593c10619f267668aa33864f54c1ddd5db0976c37d66b28c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:d4fa7d20123560c3de04d115af3af64d7fb5e4bc3132b5da7b98426058e6245a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:d6d698017792289050e2b5cc36e30f7c97e9acf8b50c88a7894651a2f4e56045
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:776b114158b71a52e5577596b04962677ba842b5d2eaa4363e965817e9c3b120
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:4f9e1bc20c23612cb5004e80273c5a5686d282aea43c361e4f5f25bbb944c00e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:411366251eb8c28c36b3564d3b3f12747fa03743a2e1a585b07f1d23bc0a676b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:ba26902966be89254a0591828ecfaf0b7de8e964ac5c23fe7a3249e7a89648c3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:6de60e9d4f1b9f3334ebda661b214904a56c64a77d81183b16de394b4c07c081
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:593c50e6b89464f30c61c786daea8472b8f08c47e0ffe62d6baefb15c6a5c533