Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.27.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.27-debian-fips, 1.27-debian13-fips, 1.27-fips, 1.27.4-debian-fips, 1.27.4-debian13-fips, 1.27.4-fips

Index digest:

sha256:0f72b996891cae4990a80abb82c38897bd3829070efe1c6ca479f85fa9033eae

Manifest digest:

sha256:4201083d52bdb8451e6bea9e67e97be5a6dcf5faa67c2cc6d417b0749db8377b

Size

38.80 MB

Last pushed

16 hours ago

Vulnerabilities

1
0
0
0
0

Support

Ends Mar 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:c0e3078c2b440782cb8fafb244e08a70dc09cfccaacfa5118dba191c01f2929a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:ab5e4472e141abc4f168a94df54f9ac19e389e72aa05d80dc18ebc5a6c33ca7a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:593480df1415d2e598ea98649809b04e08293501b3a72b9e3437f41f0dbc1314
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:ff941623f4ba818217977b438f5f3b652461f54f8cce33b15c17bf6ccf5f2544
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:740819af969fe89c84fa030569506be96ac5f21384f9aa77db4fb1922fc09568
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:7e0542fe35c4e4f8c14398d71edb7a702de43ff018dcb7ed11a99dcaf41f011f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:c16f16ff333b1a26e492ab9a0877a10456bfc65e206aeb23d18d64ee3db782b7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:e52a3d4037435b94db17f4ea51217dc841ddfb6e393d1bcf538c79b972339aa1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:9e5363f91b08faadab2c9de71c1885ad2761f7ff83fd7d74d5a55b43e6c4d76b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:2999b1c3855dfc42ba8eaa0d515d1f5484882893e8631072a27202ff850975ed
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:89828e41866dfcf1ea6b3faa52c943f04ac938e90e548a542ef46441b5004af9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:0f2ac46abd2edc70fe5813b33f359f3b808f7e4535f663e88ed4fdcd457e4628
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:15358e7ec75a7cd6cedfcce43f44d6251d09185dd976fd25e33d183f04b8e504
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:713d801d56c1d4c890a2e4240cf74e90321a76019bd61bceda9ffc43900c6f66
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:bfe41625fb042ebc095bbfda7d8500fab464f3fca7b1715d91b3a9bf1bf4cd4f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:01d9ca078b154f101121d59bc378ea0c3858daddfbbacc06d22a95b0c3e4c1f1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:5f64a62d78d9975168327fe3081228db4ca857753a8c5580a5c6eefc1c31bc10