Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.30.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.30-debian-fips-dev, 1.30-debian13-fips-dev, 1.30-fips-dev, 1.30.0-debian-fips-dev, 1.30.0-debian13-fips-dev, 1.30.0-fips-dev

Index digest:

sha256:103e3235579bb437ff5e0814739126db715c8de0921ae6c5a05cc86a51afcbe9

Manifest digest:

sha256:27d075ecf99e083d5c5cc38af213251b04c2cb08eb195ff2236cf8349599234e

Size

86.13 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
2
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:cf30b2e3ccbbd862a7d0461315ab9da036556e3b6d7d3fd8ce91a9b8179f0b82
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:7664443e3cccee50e8d40de578d10dfe1d40d54ff971ab158b7afa74b62459f6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:d8c2f543b86e17fafb0bed004903ef154a098d6006c307597826e732a19cb1fe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:7942908dfbdd52f4dab2871ce9819e78f28fc74b5536ff0d1643417f9b4b2fde
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:42c36bdfc0cfa60b15c6d6d213d38169f374ae3157c322abc0faa82a7d548a68
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:7d5ed93cb73b0ef7f134ba903ee0258886a62ceee068e06a231f25de578571a7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:dd185a1314ff24095a91e4d0bbcd4c4965f1e592148a4de8aa055fd6ce6072b1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:cca68cfcb0b11cf5205692810ee9c5e5b2923eea6876c74798404f12fea8b4c5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:d16610125c2e9f0615a31bc43dd5201db563d4f6659b79edef7416c4eef29c07
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:62e1f9cefa54f33d9f23587a580cd8b064ecdbda4b1edebbe6e35e3eb0b8b970
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:febf2595a4212bdec30d7a1de5f041e826c67ee810c2df80c727e44aeb0abbb4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:0e90b2756d9a55a341350f59ee7f119c9406b1f342b8a0f2643dcb42f6290d37
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:67ac151db0c3a4ecf45ddc283cce39a4507e8e1c718c39b69f90007d83b30b35
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:87e6ebef6f733f5c33127a16bf0acbfdba452ebad4c438f0bbca76dcf257055d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:d537a645aab4480432bda408f7bba6f38d9cf95d2ef50e9844d8a3799a9f0a27
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:5d2b7c7b308e6a5024731151b65b1de9afa62843f189c85662e7f0d38faf8dcd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:c8079eec1b1d772c81df7e13a7448e0d8e6f8b8daa26bfba9b0930e2ca6aec8c