Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.29.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.29-debian-fips-dev, 1.29-debian13-fips-dev, 1.29-fips-dev, 1.29.2-debian-fips-dev, 1.29.2-debian13-fips-dev, 1.29.2-fips-dev

Index digest:

sha256:3bccc58bf8a472ea49f1e4a0fcabcc2bfd4a556ff3afdbeb7b817299a6bffb1e

Manifest digest:

sha256:f783ccfb8bc9b913fa435fa7f3426a127bbb0a4348faa617c0a9458145ffb9b7

Size

85.85 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.29-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.29-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:e88e1714e5933ca5a31391a9bbfaf88d66952d1d06c63ac431dbc0427f4871d1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:59ac334f88cd0aa48f06281800e70af515aef7aab5990895b603aeae388553ab
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:b75926fe6b56ac29e098e58ec315e49baa099f0fe72f22449caa629c0fb35dfc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:24674b652e450a27c31b1d5524b93e5294b2394db6b33e7d1c6774d59b730fb2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:9eb6cb4b3602216a4d85b17eed61b671f45c621c72535a6c3fcceb2d8dac1eeb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:b7ddae1aa0a7d5e0b4a76742049a6872e9657394d81ca78d2332544c9a69783c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:1df018404993e71fbf57526c89ea90ca2bb4110c203b613daf3ccef2fd273225
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:d56a51a3237cb83fae00165021de3c9a1a3fdedc264ae3f8fa105d6c177a39d7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:086b0e2ac19c6f087de645baff42c851fce3fd8838d02295bc2c773eaee718d1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:28996b9f16cac7e0d4042d62509b0228510d91c37946a97aceb4d0055fa2111f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:ec541bffd14a7b5c3f01d3eaf18459768be4dfa64967e45bb994e53e84c0c2e3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:c00b5d132658ce13b17c87ba5cbb13fec8e28a2b75d1146da7b545f029e5e28d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:45c66175decc7412c1951c61a985cac2eff2e8c597519834ee1792dd19790a74
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:b3f984b051e45852c59448f799399eb2b682667b4576bb51765e4226927aee7b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:a458018c0f9081fc52c09f22a198afd1ae2dbcab610bc9f262934171b3a309bb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:30690d4614a955cf739f3092905d85a1b503975723ec2639923661e009b0515c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:a0704dccf4e6c2eff124da39599c9f6932db9f8c209bcf012095117a88a2b600