Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.27.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.27-debian-fips-dev, 1.27-debian13-fips-dev, 1.27-fips-dev, 1.27.4-debian-fips-dev, 1.27.4-debian13-fips-dev, 1.27.4-fips-dev

Index digest:

sha256:061d7c4ce85cc6e49b073fc1d9b3723cbdc66d079b1c22416218f7d7ac0102d5

Manifest digest:

sha256:2107db8496db6d17477c98e8aab5cf65a442341e7446b41c8ad615f41d51364a

Size

84.92 MB

Last pushed

13 hours ago

Vulnerabilities

1
2
0
1
0

Support

Ends Mar 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:b82ee4678b70de713c0f6aa016a0b836edcb004787f3644ab77ef6c199f37fbe
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:87ebe4b402bfccc63f71c5b89ef5862c32d1dee320149b6d31e1a142474b0265
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:d5c432061f7b464d7b33144c6a5131dc39d0b430fd5db905346dd328141b9c6e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:6bdf7cd0a63f96b37f8959e5060d00784191d444d1177f0a82ba9b1c992617bd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:b8821744ce27e6ab40c05c3a6398a92d6bbd83674b91733fd5e37bca01b6b952
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:3e3c538e4edff43f1d7bd6585bcd9db4f0c6d8411717b3bea51f6b21025ff98c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:43bf077509f79833e46e846ee37edb3a625345ce2b0f544fc055063b2db78a18
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:619e44dab1bbdc237fc936f26e2c0702708ed8b45731e7d7866505b4a791478e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:f0ce4bce460f3f130d4e4fa4089d4128ba9beb56f80569de6c36b6c697e11608
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:e2c184c5901d4e3acd64bee26f4595f1d578f011f815f9c5154b39bdeb8639ff
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:8fc4984b493bbd4fcfa6d20da4beebfa762bebef8734d6ed92735a5c3192a278
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:34b8900f23b3f92b418c9b77227a096e83b3f62f38e2d66b82ecba99b6f78eef
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:90790bae683793b673085a8928fd3fb87df9ac4ba6c7586f6aa4575e40f18391
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:87bc42eeb042d1f231285c006c88c92bb779dd207ba718a83cc375c04912a1f1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:9ea526fb224afd71442262b1121b3ae98a212fffd777ce9cc2e08e602396ee76
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:8eeb85436fa06d59af84e3a61a4da798272388fb8c114e79d601ad96942db333
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:01e967934a4453e93acb1750f7258bc0aacc48dcb59c63994bc610e2a8370dc2