Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.29.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.29-debian-fips-dev, 1.29-debian13-fips-dev, 1.29-fips-dev, 1.29.3-debian-fips-dev, 1.29.3-debian13-fips-dev, 1.29.3-fips-dev

Index digest:

sha256:819dbfd3b5aed7dd946e8f718eb259d56921f030dbf658bb8b5232f126be8ae1

Manifest digest:

sha256:5fec3e87fc947223da59265a07fb6ff86eaa0832038481627af2f6ae68f02029

Size

89.47 MB

Last pushed

2 days ago

Vulnerabilities

0
2
3
10
0

Support

Ends Sep 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.29-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.29-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:0566697729a7cf57003981292b43f9bf6ae5ecd3de149fab598d1431738acf5d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:365fcfaf94e48bf9b15446e55a475d8f38d479448b255fdfb4dd22ad298cd44e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:94a4b09913baa9313b261a811f5e11d622c75ebff7a007e099b9d26b8a02e3b2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:a9f80d590c1c456aa2e338f38d045d00ccd3e5de38dd80c52e88708ccaca61dd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:b0a8b0802c1f24f0590704f0e6e6f4779f76d3617ac93382dd5929300fccb24d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:9f2f5f7eb6257bbbe604dbad51e77ce03c3ccb13e89c6d1b452862afb3605463
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:9259c8b885fe89c6e2ec803049181e892cc1cd84cb35b78799f77cb702b2d451
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:cf966b6849ee6f616c3fe5323ea010b12ef57a3781c98e81e0af1286a65b216a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:b924f1775b7bf0b7584cd2fa9a91b6ecf7e0f4b9035496bdb47a8676ab862e13
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:98d211fce3511b5a0595552a37229d69f478c5840d3295727baf919dcec624f1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:35b42ba698b4305ab4f97dc625898c0f3167488b3884e007ab3f1554573271ed
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:84a706ba286243f3d0102fdadc066873a5055a18cf50fd4454846b9c6d799ec9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:99e39aecbead3b304a83955bc32a7d38cdb62852856ffc9fce46833198729c0a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:2dd8d22753486415e18fff581b72f20cb65367485877dc40f2bed5bf3113d5cb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:0b5ad7c3444c59742cbd360708e26a4342c80b106fa1a7a9b00cfa8a2d502c32
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:25eb384730a6c55d579424d03702c54b538c58151d66b39585e7f418e66945e1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:9bb55a0b862103cb388a5f479ac2352768850ee5aafadddcdb22f4156a383485