Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.28.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.28-debian-fips-dev, 1.28-debian13-fips-dev, 1.28-fips-dev, 1.28.4-debian-fips-dev, 1.28.4-debian13-fips-dev, 1.28.4-fips-dev

Index digest:

sha256:a779ae41d7e69305c12c0cd22964292428dd78996db51c645d339b3e8b244620

Manifest digest:

sha256:57aa80d50f250222937f0352b039ad94fbaabc23c58f2c0576694360400c751e

Size

85.49 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Jun 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.28-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.28-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:3c9ee915242e009e8d026d969b755951efac953ca1a432401a24dfa2d08971c2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:458a15fd36da3c1489fb299dd23fd3ff84e332cc30686cf88391819e7a967226
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:fb63204505e179aaa4efc6dd64686fb248c2472138a206df8348863bdd864fea
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:ea66a285abf9456553fe16be29443b7c9f27d994aa8ba2e4c21e4f820c29aa9b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:02b43e1130b0028ab4eb7387d86b3c18d85fc9c8fdcec2a210aef3ee0c340f27
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:933933d1ef4c29be6e5f8923c42a5feea8682d3d0ed0dea0fadde09d0eab5fd8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:9522b598b0e5aa4eaa829403844e44148171bb4c7725043cea0b3b39c1c3ed80
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:43713ddd7725ce5ccb6dfc431498f2f330cdabc54abf444e957805c819955286
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:4cc62604fb56e4efd92fee5e05d9136f85c534cd1498d322f130288ae5f59814
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:6ac471443f2c95cfb095e5712466396389b8aef365a77cbdb9e43bb2994a8905
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:1a9d68c732f134c6ff55e2c32a18a9ea7db769017a063a006032f2df32f2475a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:9e15b31433d0086e5ab4634479e0e90a14feac11cbc7c8f8b1d2de539de3a892
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:34040b8c6ffec17b5c68fa40ab214ec7e79d80f44803fae00f76d5192792cea9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:1bcf534d18f08046a97284750ba7b450210c14a4df5d88e028ab732bdbbba7b9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:3aa5602795ced7e4a261427029548277c2789ae9001eaccd4b0e70d6972cc943
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:e4788ffbcc332b39f66685c04f47f4f35fb234cc3600b176826a48dec4ed7d3d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:2a72882be73a93c5b8524f3e201aa42c8bb9f39048b67fc37096abd178ba8e0b