Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.29.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.29-debian-fips-dev, 1.29-debian13-fips-dev, 1.29-fips-dev, 1.29.2-debian-fips-dev, 1.29.2-debian13-fips-dev, 1.29.2-fips-dev

Index digest:

sha256:705e2e31ef824a2f2721dd42157ea25c4c26dd0d4ec01da8458c05170c9fc3af

Manifest digest:

sha256:f1e94f1b2a16196dc91340475040b90494382c1c8ff57368c871dbea8355381f

Size

89.47 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.29-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.29-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:15bc4d5bc99301b42d8476af356f8d6ae04dfdfc991e74b7d427201e4981fe3c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:54639b6c5b1f7bd565fc07275b74b440d4c000f501db4cc475914ef192d6ec53
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:d9285df890f2b2604750b63e0e88c679485f70f1e986364cfa9930c50af3cefd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:989eaeaa9c42677a9fcdb143d82ac7fde78356c7e6697080dd512a83119f7cb7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:33ee03207584b433545a2c9fa8dc034773281cfe2efb09ab6d85a2e559152689
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:e742ac07fc736e6860aee328e67b3c59fdbd12587635a81cd092d88228681b25
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:54def9e5d04f8fa4e79a1cbf1d9b11a0b3693d0c339f522f5a035969c9be1a36
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:f7b27da256f8a95af6329dd93db6251ff40b5209b87093b3b0296e839f6f12ab
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:13f86bc8c111a9329030b35708f126f95d9a720f9994afd14dfbb305661c3b0e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:bd03d0262f4b40eb32725bf37b634d7de61860f8e0fc52e78875cc7e43a5a4cd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:4ec0fc706ae65d675eee5c5d1386143995c03d582401f343be08967df2fce72f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:c1f77034358499b11729c52c53a7a9ca50b666e6f52aac95f704a9435a198280
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:5a675493e242e9946fbcecda36384657f1e48f96410510321cc5d96cffbd7bf3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:e5f3dc0c4e109979e56bcd24b482d6e54158f20fb3a549725251f1e61f5ff134
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:2595a71406d3295e3d9b4b2f60a7ea73fd2c3974c36302b9dff7dc6ff6a92267
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:cc58991ff1f043acd7a4e62d8d84afdd4bd480535a761fe43b4c4da7f4221ccf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:12933e3443c850b947bb8804e6b5e04091478696972ea77007ebb2ab0ac9a373