Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.27.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.27-debian-fips, 1.27-debian13-fips, 1.27-fips, 1.27.4-debian-fips, 1.27.4-debian13-fips, 1.27.4-fips

Index digest:

sha256:672ea8fd20067ecc5e65ceb359cc793721e2667d5ed4325dae0fa82224058fde

Manifest digest:

sha256:86e6c40b0dfa407f19d9d5a5f56dfff92cbef4cb81b24b1a2988604b977ad0f4

Size

38.80 MB

Last pushed

4 hours ago

Vulnerabilities

1
1
0
0
0

Support

Ends Mar 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:98c5900ff32bc6f5be0d82027df31c1720d8529fa3b5d32d1539ce791de5fa67
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:e5c5856b6832473e0536a1ad3b73c0a60f053ac988652ec0c473688c9ec8d00b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:6f2bfd43998302c213921d55f6a1c553f3821570ade256a911485726666a931a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:90b641eea8dd80e6202c87a5fcebfa6d9953a2b3fa3caaa8e914bb79fe96c3cd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:205b3f47ed40ed0bd868fd78997ccc2cb21209685dcd7e2a41a0e68362446a90
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:0f1e5868aae14ada939c53b72eea0aac55cfdb1a05f4df71633e75bef3079700
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:f721bb61ad122be7e3970ef613c7583029e99ae192dee2cceecac064e7081974
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:3d6bb3ff4ea033976cca9a56c226a003189b475005b507388990ff6d15c27bea
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:9a7e2a30c544a2b2f6c81443666354128cfc1710c0084da3edb65337116c9af2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:4dd1c8dc61cc510f38a4d1228046ff044ca58718c656971f96e7276bedf3ea7d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:558b9a2532e1144e118bc0ff8a9bb3c0bcb6cfb4ffa5f77993a84b96cbf92b6f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:948defcda4e9118b57acd3388c4b1b6cf3e90b77a17950873bb140082f2853e5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:d5309d8f300747724042d1d8638ac0e04a80aa7cbf7160599c49104c39324a50
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:4837247868d0e17f97ad4a8aac19881473cd49c3e2cf91445d5c3083312f1ed0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:1bcdf78bdb9a13218a0fa5dcc0d6cc127ac4755e6ca98d2d3257e6672e0e2269
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:fd001d167e3d1e8e419ded52f24353e5e5bad7c0177d624194d0b534de20dae6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:c581e56de2ef3ed0e1fdcb2f524047a30eaff1bce64388b71ce730bda32b4f16