Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.27.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.27-debian-fips-dev, 1.27-debian13-fips-dev, 1.27-fips-dev, 1.27.4-debian-fips-dev, 1.27.4-debian13-fips-dev, 1.27.4-fips-dev

Index digest:

sha256:326e6383f5442da874b38905b20dec0447fb9c5c39334c5eb5e50108139178dd

Manifest digest:

sha256:80641d24fe1f3f3eff9ea7742da8aeca314e7d47d48d430d6f21a83847c30cbe

Size

84.92 MB

Last pushed

2 days ago

Vulnerabilities

1
0
0
1
0

Support

Ends Mar 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:d197726d25bcd03f88d5ec30570594399ec7db72aa2b4076c0367a20b808b805
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:db29ffe9e18549d9fac5e02c827d997009a198d67d6c22f130ad1547580ac1c4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:4a31b14aa43f3c5102448f4f079dd772431d1d43f533d6edded17438d4bb0741
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:93f686adf23be55f143c4f321bc052815f9669b307e5f952ca7afa8cb88a7e78
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:7820349c2ef87fc55722369d3bcac62ee1fc5191f25d611fe2841afa33a51ee8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:d2110143b5e8d7178c849b200574dee74d4628214df53a5d26f89afd7bec74ac
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:bc95fd8bfe2f0824e67c6d2e142913cf693fa3bba3721cf5d46a1eef56e17bf6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:a16d8a3155a55010b081ee3bddee7c1795699ca5abb41430f5bc767767ed6d28
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:f31bd2cf6b61bd4fd3c09c66852409ab21bfb82ca73ae1a028cb7de99767b993
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:794c3763911b68ee225c1555f6bc768c1b7b382530713d8b978dd1f2660ef750
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:c803e8178fc2d46b47097b0dbf4787baff873bbeb87cfbac6ed2598d724fa195
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:6af5b472774638a62b4a777f54c85dfe348f739faaf4afc9ff504473cbdc40ef
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:43d148befd746dea3a6b1f4fe18f189b664861094c40a08808fe4f2666fcdad0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:df8c15f3cfaef41a80a7f5efaaf88dd7b23446fa7bad9b5a4d14d28f3809f625
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:8fa65f8ef8276fb8fac14841e69dd97dfdff05ccc804a16069c15f9aad235dd8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:59c856a9e906da0ff4254860b7b32f525e1ec6ac1f221ec0fc92430dc1973a37
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:1ae5238abdd7dafe91bc3e0e6515a1b9e87176b9b2f0d21dc043e218f3b5dffb