Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.28.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.28-debian-fips-dev, 1.28-debian13-fips-dev, 1.28-fips-dev, 1.28.4-debian-fips-dev, 1.28.4-debian13-fips-dev, 1.28.4-fips-dev

Index digest:

sha256:7cc09b8c04d8c3cfc35d506d3317444abf4cc066533f47d034b78113803e4753

Manifest digest:

sha256:718fadaf7fa234aeaa67a3c0ed9c0a3f5d8596745c885fa47ee0772125a7b9ae

Size

85.49 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
1
1

Support

Ends Jun 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.28-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.28-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:f10627f62992099d8161e4de09f344541d4edc054fb5440151653c569f172736
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:34a3adf93d007974c256aabc66dee062ca3c31d722bfb4cd97a0690d85611d9d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:2703783770af4e34b82e0a6d55ddd7c6fc12a637a35e866fb82edfa79adb55a0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:22585602007e68afae6087ad5bd5997297f130e46b3e712e41b5ec50fe9c1c74
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:a64758ae25ed983cbabc68d023224438ddc955c58ee4ab0ce3bb108e96c3ab54
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:d436efff26c2e288114bcaba11d58954c1c161797c13640b6b3bfb98e6aaa3d1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:a27c17e04cae798c0df624c3be903f07fdbaba2d9c04df2aae0e83805da0068c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:f2743e93922da633c102c0f63e2390a1507195f333c1a7fb3a30427be524cea6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:a48e7a87bfeb6744dc3ac9f168a9a10699577143c9c72c1b56dc263703dc5c14
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:72c1d802c791c1a7b13538abdc39620e1d3d8a9ffee23e81acac9249d5d604ee
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:cdc14852d63fc3ce2487275ef8cb31ffb074a938937b2bada270934c927d6e13
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:8bde9db659f4e530d35b219a565e3f22ddec00859c3001304e2e7ae36dac1ee2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:c42979f9d5ca01e0ea25c3da125c628645a893838858d78fa55799ea6d8b4e3f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:b74949550169f50eec9c7e04cc175c57682ab30f3b5b3614e2abba93643e8f1e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:d7710ba2501b44a6653dadfd768e1f4995edec5fca505b8a85ac083d5b8633b5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:d25ef0fd72b8d85b7d91758d069e4cdd77e0e230656c3d760429c1c91255c29b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:ffccf2e47f7e1ff684f47d08faebb80920b50918da9604b055c3508f1a6af4ec