Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.28.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.28-debian-fips, 1.28-debian13-fips, 1.28-fips, 1.28.4-debian-fips, 1.28.4-debian13-fips, 1.28.4-fips

Index digest:

sha256:548157d56dcd658846e8ee14b8a40a19aeb730196338f74c990241f35c060945

Manifest digest:

sha256:1af797b661a4c7d5c7b30269f6ce4e68dc133c545f8bbd180bb2746990d6c805

Size

39.16 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Ends Jun 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.28-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.28-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:37ad7270bb3d2165d089f36e5fa99c29b683876805590e75bbf0c509d74c3b80
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:86c17b9db0ad3ec30bc36945f48a2987bc3e2a039ed5367d8e333e9a3271b3f2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:a94640c215c68d6b14114bf12ca1210de9af61790cab518f9a0a3df5bdb33016
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:6fc687eb514a00c25f1eb77797d0e0ebba119dd4b5c68aefd28256fc287f7a3b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:63d50e6017edaf02ef143b27e8acea01cf1010d2674d90a2b7867901459767b1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:511bf933ab779c6ee35e96f779b707bcb4ca91c94eb0be2575617fef45c01e02
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:331a136e11e30b27763f21b4435498aec1e6b1951dae34672d533a1121083bd1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:e68396eadc59d5209eca18e01f89536cd9f95131685cb24847d854cd019b308b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:13cb22051b875a24059d66793206370090e8dbbe0708578a126f10f87d03c742
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:c236c02f26c89c53574d3eb6967670d1051c3e58172a99e6455025908ac13dc4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:1d2b5b1480c4438e235be2fe06a100e1e30b5c87836c2599cc8515ac8bcd3332
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:b88360f4dec6d1aebe13412892df109c218a8c18f2ac51bfe702de00763101b4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:127fc391cc288be9d8674569085d5749f280bca60185661a3fce6d03226e0b9a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:f4411b7202687b67fa02a3f575afbbf53a34eabe8b77f1d9e7a9074c46b9384d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:309b6722741727cdba7998be8b67d4867aa251a6808dffb3710c3d30dc608f16
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:c7fef2a7d570200a1701d4c300276b60734574f19eb584526abc27c544e3730d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:d0ee14abdf8d7465ace762029e47729f6327f8962af6309c3bcd1e42edc4c33c