Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.28.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.28-debian-fips-dev, 1.28-debian13-fips-dev, 1.28-fips-dev, 1.28.4-debian-fips-dev, 1.28.4-debian13-fips-dev, 1.28.4-fips-dev

Index digest:

sha256:039bbb51f181424157c7aefd5184450005187767d6609dc2fec8c14f285f411a

Manifest digest:

sha256:54ab79e9ef78cbf56665af43539847e0bfbd8bd668b930574090470ba69443d6

Size

85.49 MB

Last pushed

6 days ago

Vulnerabilities

0
1
2
10
1

Support

Ends Jun 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.28-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.28-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:2e6408387a3d46f58827ad9f528b528aebfc85174af2cf60a0f13d3ee8ed9b75
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:b9ecc8bb2f56a8e2a837ec9afaeea44892a0b84499f2469d9493d08e05d3a378
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:1569aa68eaec8d3ade90d498af5ac6cb15d48a822b7a9ef1664b70a1d294f3b7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:58c8ddff75620a633c99015f2825203911e040f528ebd0c3fd34abc0aaf75ac3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:1bfafaaa30e017b0b2cef9f03a112d4ac6bf654839813b225cc8b30284596fcc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:7c3d78145364a41549015656679d38a12a6b67027ca6b6c8a6b73004c612fd53
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:26c7f9e4a5c419ef7eda676f565ca7a5257cffc821ea85977b1b5a6e2ed1a018
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:07c0dee56d2ed95dcb7b401004eae46206c4390236cb9991115c4f047cdcabfb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:17abf90d594d81fab8294976f3aa6f8c51a7c6bb13299cb516d029bfa493e90b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:feab4da450b8e602f35a2669b147174844e99ec852827622c58b0c89faf00758
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:0b6f9aefa1a4459fa442583bfc2471fe0c0e54c2d059fa673d2ee480e3969c33
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:9d54ddddbf1393a255ec47c4926ea658fa7fdc2ab2951852839949cfee0b98d9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:843988c383d7bf0204b4142a9e5af09089eac71ec3c71f5822a27b90d56c676e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:a68388678fd31130b1562b8a76b8323e29b646c6e629f57bea795f168ba8b2ef
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:0f0baeebfe01b4a98f6ae06cbe86596a7d56186c0e3ed275ed066e8b94d22f32
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:adef0d49594b91966f1ce7fc9d8e76b2f0032392001d6c0f320e89787c0b4534
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:1ee0bc226008a839b119987fb069877477db0ade41e943e4ca9ea696786808e1