Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.29.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.29-debian-fips-dev, 1.29-debian13-fips-dev, 1.29-fips-dev, 1.29.2-debian-fips-dev, 1.29.2-debian13-fips-dev, 1.29.2-fips-dev

Index digest:

sha256:193981acbb05e9090a6d93170287e9856f2ee45f6785a50d668481781aa6e0b0

Manifest digest:

sha256:a6b102331e12c97969c4005230054f31998bb860fa24020055a7c7d7981f6cb8

Size

85.85 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.29-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.29-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:35cfd291917bcbf096d6eab43f0a4fd04b06d3cffae96266d162596bf475bdbc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:cd4a353641e91bd7a10127dec9070eaf5358e23af9c34fed5fda34ea2a641d58
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:59c294162caecf07211bff15c4907c95ac82682d851eacd1cde741bd464e5dab
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:366bbaa10233a12cfec7fb1a721abc3de3dabb5ce7eb9564145a4d72b2f4a61d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:2cb0633f65a00a54f3da3fe324f31f73e67d547815e05360db173fa8548bee80
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:51f5103b5a8579134e3de23f1edf9ac5b0cc491496d42f5fc82f750e08e7ae9e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:16ed755d9d3db36cf116c70e2c430d38bfcc6820c16dd45fc9f36e666d99f98c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:60a718c9bc13c40f4fdd69394b83c6802ff4d2dc318127822287563ae1040036
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:84eea6580de4461b388bae48e181918fa8ce6306d1cd1af826ec16cf24502de3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:5fb0236b8e3a4a7901bdf0c6d0ee272b404b878f031809e40c25ed8ac2942567
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:1dbec7297dd2f3ca1d56a6107b914ab57fbb3f9e50c28e5cd38f124db64452a0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:ace0f9e558a6540035f137b26dc1ed949f87bd14e2ad71328c89b06501fff4f8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:302cbf9899f6723e1ec599babfbe9c44b2285c140839dc514c81dec9ea8233ed
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:70005f8729c6381bf8a965ab2a1fd706f3d1823da0ce25fb5351b0123c73d257
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:cbeaa675395e96caee073678c1ab0adce166de951db9e54a40048d3f6cecddb4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:fc8d2d8f4ec5d3ea4613d9b3bbbce0532386561bd61af959a011eb65627dcd1c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:ba12e4654080bf90bfae2098df93fb2d0229b2baf65936273bf2df6f2844d794