Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.27.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.27-debian-fips-dev, 1.27-debian13-fips-dev, 1.27-fips-dev, 1.27.4-debian-fips-dev, 1.27.4-debian13-fips-dev, 1.27.4-fips-dev

Index digest:

sha256:517a52c0147e091dbcdbfddc8c858ad513d4e80b0d93eaa43ce9c401b5d91fce

Manifest digest:

sha256:1f97c21214b97102908075467dec59622f6a5cf4804caa4ff3830b56eeac481f

Size

84.90 MB

Last pushed

8 hours ago

Vulnerabilities

1
0
0
1
0

Support

Ends Mar 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:c71bdefa40351bd06f70c0f496137a2ceab16f55198df259c160bb4c885f70e7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:ee35ebffb79dc54ac59d9cc2b8be728ff437c8f362e9d90bf3793a5884537e1a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:6bbab69d92bcd7f81c20cf0e92ce9478e66d2738d5a3c0c4aec9328ef7074b01
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:4bcc54fcb9f83ee42667af71270096216ef85ec54712ba02de923b704365c12a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:2c1061a4716433dfce62d09ec9761dc990ad3f11bee780b403b9b935d7d9dc64
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:0bab028491e659791a15db218ab283dd2ae27224b40a426a0584371024eea64b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:0b3860651c0404052fd48a1567b3d1d465a2e45e78ad3f4a2af9046d1897258b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:f091e52e23fb5843f922b9fcd5c7498f489f0a23868a376be1f1a506d955c8ff
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:e925fc55a2d6e61eacf83bbb73f9baa88967f9cef6edc31e530a79b1b95924c7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:9d2860d7b341089c46192dd8e991351a1b52be5b21b92340b8221e1c940e99fd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:5139093b11585d13bb85307f898d16e84dcc608f9fc25034cac0e08c43bcd907
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:0c3e3732013141c57347e9e21d3ab1d47f92621024e782b4f42fecc6010b096a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:406fb5a351448eec2e4858a7d232f9026b5953d82c901a15373a1f89fbba9473
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:c19192b26fadc280c15a50bf7988af5ba4c1ffdc03defe02c627221f084c16ed
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:4b089653b8e39160024f8d2510683bd4f628da4e7a5272b996fe1192b7625aaf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:8045e0ffcec480602f378f91ae5ce50229674198b814782b5b66ee84560e9721
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:2fbf0637d8fa20d5826f031ddc518de4648a6834d3056dcfb9beee6fd553310d