Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.27.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.27-debian-fips, 1.27-debian13-fips, 1.27-fips, 1.27.4-debian-fips, 1.27.4-debian13-fips, 1.27.4-fips

Index digest:

sha256:2ebfb05e085942f1cc59fbe0f90f3c66978da3d306330c5414c7705adc34eab7

Manifest digest:

sha256:6d0ab421ec55bd90c67f621cb334968e65e7eb4f73e103b8b5ea3de1d3580677

Size

38.79 MB

Last pushed

10 hours ago

Vulnerabilities

1
0
0
0
0

Support

Ends Mar 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:4e85779dcfc088849f0f9a5cccc856352b82e97aa535245013fbe0bc0bfbfa0c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:2c029bf1881b24b9e44fbaa1412fbdb993d1ffe42d7cadd1ed916e0a44a92d03
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:e882959b1646b25b2621b3930bbc36c56d781d83f67865e1e6d34153129827d4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:3f026eaa8705763ac4c90b3b11e03a16c1afa809963f69f2c07024f0fae2727f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:65e441c4dcd3cc07d7046dd62fb12f28ad2a9780baa244e327cbdfc5f9bca8ec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:9c6002743f04677913d17cd1edd7b39de89ac92877dd325e89135dd1bc3ac03c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:d5c88520b7f0bead532ec35cc0dc89138d681a3dd4049c1fed624fac1f155841
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:b387a7c3e54fa0446e3ceafa3a2333143765ecca3446ffd6b39c4a980bfbe9d6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:30e4107b30dfe3a8c5545517d3e9a7694d3f0213d366974a98ad17b7ef7575f2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:90f326964ef75ba14803dab6bc0f14c59aa3d9f37c394bc2e13f0bd65d22d08f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:32dec51ed338a34f3e61759a55d1f04228c229231ee86b169b556f25d4421c13
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:e51eb50f3efffde75df6b4e2bf7ea6db5869e9bc78d3386cadaa216a6b6254ee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:8648c308d1111f5ba2978677f94ef2a40c4bb1dad2f9ebe5690d522856695a28
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:3d6327b82f1fdd1f5a52ddb22a67b4bc8948fb36d26d9fa82b8b55fa3f75dcb5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:21f022c1be99758c52dbac9a630aaf3eaba956c06821e80f8084118b7c8065dd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:c2a998d5af7d8bc461fba6c9b0e684fcce228eef4819daa5b1be7a82b6fa034f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:d99da7319d38ce76756369d1fe5314832d5c82dfa7ebdfe9bd26ecd95ad50b0c