Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.30.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.30-debian-fips-dev, 1.30-debian13-fips-dev, 1.30-fips-dev, 1.30.0-debian-fips-dev, 1.30.0-debian13-fips-dev, 1.30.0-fips-dev

Index digest:

sha256:00245235e811dd008c922cdf59afa36ba1aaca31411acc0356255d91a0cf85c0

Manifest digest:

sha256:76d4695f30bb281bab509b1670828934afa67f92f0b47276288f751376881824

Size

86.13 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:285f775b87bff3ab2faf7ffa2bea795127e5590f7de2a65e38ae3dc1eb84ba12
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:c452f2cafc28d7bc2b6b074fd49a703f723f43fa50d1cedc0dfaee5345baa1a3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:158a13257029a86dfe17ce00fa021c691fb1a23872a759b1637994703c36d031
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:2416ca746d090f756fa687b5ad228532fd1a52f86fef4af750b0910b579b26a3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:d70ac28a8ecf5371111d08c0ce94f2001ebb126877136375781150f353c6d0a9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:7b01f97773e0b07b622619bfcbceb182f3a40fb180a12254f12110ec463d051b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:c254a0304d2aeb9572d2832cad6105e70d7f0dcb3aff981275a5ea5d0f2fd492
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:0f20e67c1d061210766657dd22db20476019e9a31ef6c973ba0f27d4bbf83bb8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:a6b7d0f5c347b0f2a0beaccef177364734b0989483d648dfd3130beabba5ffd3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:41463a3fdf967b5ebe90a2c30200f5353279534023bfde6f4d37bd0708bd8ff1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:9380cbc2e5721ea5d4a2f8d1a9ec1dccb55fa6c55d6f4f9740f4d5532d74cd15
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:41f42d861cde12cccf9b9dbf3163d3d2cc6e257c996ac887d1ec133aa7f9ae6a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:5b4f502c562305fa1d031027edbaee5a8a53b76acbf3de61bf2f6ad3465e226c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:8bb9b0e08309ca0fd5367a12ff36b60de085fe4e3f81299af11b752e5a956adb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:a05118ea85f4adcbdcca8e6564b5923063a2892b7b0990fc0ede7955cafa5a11
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:a5ac7313609824551e24af1a9bfb58d3301e17e2efecf40003675b7156731496
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:feb90fd35e4b34c4b633f2bd8b59de8ad013348306904b574eb3c571378ee4ae