Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.29.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.29-debian-fips-dev, 1.29-debian13-fips-dev, 1.29-fips-dev, 1.29.2-debian-fips-dev, 1.29.2-debian13-fips-dev, 1.29.2-fips-dev

Index digest:

sha256:193981acbb05e9090a6d93170287e9856f2ee45f6785a50d668481781aa6e0b0

Manifest digest:

sha256:a6b102331e12c97969c4005230054f31998bb860fa24020055a7c7d7981f6cb8

Size

85.85 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.29-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.29-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:35cfd291917bcbf096d6eab43f0a4fd04b06d3cffae96266d162596bf475bdbc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:cd4a353641e91bd7a10127dec9070eaf5358e23af9c34fed5fda34ea2a641d58
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:59c294162caecf07211bff15c4907c95ac82682d851eacd1cde741bd464e5dab
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:366bbaa10233a12cfec7fb1a721abc3de3dabb5ce7eb9564145a4d72b2f4a61d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:2cb0633f65a00a54f3da3fe324f31f73e67d547815e05360db173fa8548bee80
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:5a3ff709b9eb42277109a2ce29470b407ea247133ceec245cbef7c108657fee4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:3f1a6b433656e275ecc1cfd444ba9864a7c9e93e3a8f887c1b0827b3e5eb186a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:60a718c9bc13c40f4fdd69394b83c6802ff4d2dc318127822287563ae1040036
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:84eea6580de4461b388bae48e181918fa8ce6306d1cd1af826ec16cf24502de3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:5fb0236b8e3a4a7901bdf0c6d0ee272b404b878f031809e40c25ed8ac2942567
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:1dbec7297dd2f3ca1d56a6107b914ab57fbb3f9e50c28e5cd38f124db64452a0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:ace0f9e558a6540035f137b26dc1ed949f87bd14e2ad71328c89b06501fff4f8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:d8b41871169d4fd18f0b1b8ac9dad8e4905b529bac7a11ffce46704b286d9a1c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:70005f8729c6381bf8a965ab2a1fd706f3d1823da0ce25fb5351b0123c73d257
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:cbeaa675395e96caee073678c1ab0adce166de951db9e54a40048d3f6cecddb4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:fc8d2d8f4ec5d3ea4613d9b3bbbce0532386561bd61af959a011eb65627dcd1c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:ba12e4654080bf90bfae2098df93fb2d0229b2baf65936273bf2df6f2844d794