Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.29.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.29-debian-fips, 1.29-debian13-fips, 1.29-fips, 1.29.2-debian-fips, 1.29.2-debian13-fips, 1.29.2-fips

Index digest:

sha256:ddaf9124fed556116c8d58e64bb889abd1a1df41c7ddbaeafc0937c3ac28e72a

Manifest digest:

sha256:0a1b459f6a4304fc4d16d591da1f752a4c82bdbee34d080dfb6ee13c221854d7

Size

39.33 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.29-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.29-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:13ec95e0f815cdf6cf7f3d92d593ee2a764bae1e9b5b21fc4746481af01d4ff5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:00e75a56e9fb60a36781766c8e26ca0704169c926331fec3328780fcaf4fbffb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:012e4ee2528d3889eacfda83c6fbdb505d082947736611a26320926b10ac2cb1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:c50686918178636cf33cbc8d3132adb51c2c17a03bf049a748f5c33ed35116ab
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:1c6b9472b4ec2250abe8065d20f0de80e560b1d281cbdf1d7293a7955fa78277
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:1d1799850aa469639dabe5deae2775a155c92df4e160dd1983f3901ecec7e319
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:b67a4c096622bf03e2eaca84948871f5c2faaf542139f1e13aa8fc491582785d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:df277b157eeb430fd28e92afd28462290763f7556d0ccb703ed960bcf3be2422
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:42250546b17a286466c5df98561f0c48dc2dde943f0f6d19d70f5a1edb6029b5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:e50a072d2a904a3d68c43be141f889254f09f79f050437f7ad7230ce9beedeaa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:61c9c75f621d0248dff26b33ab54a559a204775d1e169f0f79952da544b042ae
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:240e16854db8c5e8eaf2315652b17b015d409700cbdfdc322a8506b48ebd27d5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:fb11acd1776222617be48c02e9f75df73be32b99718658187df39513568fae21
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:433203bea690026c26ddb0eb119fa894871bc75663e6a7207d4a175f3eaf44da
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:e09512a6515de06867e3ec9b686326d2d3d54bec89e71c1b1094500028030d48
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:8ad000dc38c8f3b4e498991a96c9bb3b332deb204c747ef669bf4e4b59a2a855
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:151ff3c3722e499ea092b9d9095c0567b60f6a30cec34c7a4e171c996d5a665c