Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.29.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.29-debian-fips-dev, 1.29-debian13-fips-dev, 1.29-fips-dev, 1.29.3-debian-fips-dev, 1.29.3-debian13-fips-dev, 1.29.3-fips-dev

Index digest:

sha256:74d10c0dbb99d19f97e13b74a98e6403c1fba4f5e6d9301880a9050be444fae6

Manifest digest:

sha256:b58556070ead289ba8d225b1872bc1d93aec9cb046b90eb4a1ce53f6920d2fa4

Size

89.49 MB

Last pushed

8 hours ago

Vulnerabilities

0
2
0
1
0

Support

Ends Sep 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.29-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.29-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:b05d46e6002b89dca07d312a3dbfea204e682aa5cba54514cb1e570f0290449f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:a7f53be346e9173912ff3c783f1d9c572d5b03851e0257993f5b4e051a609950
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:83d938259b12ad78a6a420dfb827b07f2ed33fcb03279f03a13c082f1ed0bd65
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:4512d644b87737ff591ecdfaba06c0751843acfccac868a08b569e62e7d8fa21
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:0ee91e119cd549062f7b09d0445a8cdff7daa99a989bd623649a2de91ba59dc2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:c11c42e1f66e97550cc675536e3aab38bb0ca403f972c8b308473d7555c9887a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:9f921d73b10be9e136d32d2428d9c07232786b3a1b2603a1a47ec8ac91bdee06
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:24ddac82b6b6a694f6c4ef37502b5c0bb740ffb9d18c9396443171f3d06abc9b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:dc77be8a0fd3c3cebaa829e5e6d8b46f18e50cd886394dd2555e564ce3725a63
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:a29195f723df90c016007cdb0367ae9941ebb005ed183b4b1edc39d05aff6915
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:f20ef4d90d5ec466765e90ca18f7ed2bbc791ad77e029c652d83958405815f00
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:752188358dc8fd3839e1b06c57cef020a852ec56e4469e83f8a5fd1cd1377b8b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:b1acee1236c38272f64309e12b540429a705f9aa9ca2f262758aff0370bafb04
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:1684b78972c3bbb1bde8f0d944cfd116de75e93d0e6a05dc79ea38c255eb7372
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:1dc7c4d58c2c6a9f7df1715718acf07088a3c7884a569894d68d325229e61526
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:fb86c9115e3bc2e5e88debbb9ece74ed5e012b69f95a630811a77e873dd17abb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:4564374567742b9b7844ccec3b1e2ae0471c15c4d4f934b52a28fc875e386874