Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.30.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.30-debian-fips-dev, 1.30-debian13-fips-dev, 1.30-fips-dev, 1.30.1-debian-fips-dev, 1.30.1-debian13-fips-dev, 1.30.1-fips-dev

Index digest:

sha256:5665372191e63df362970f20d2f1fbae1fc62f1b3528937f6e3a10b745c03a0e

Manifest digest:

sha256:7559306d51d163f0b1927f80c600f3db4d5b86ea557b0093ecbb3dbe79b3d243

Size

89.78 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Ends Sep 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:c1fdf570da8e095dd50358976d9faffc12f5910ca23fb79ee4843603bb19a4aa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:9b3c15f894190d1dc3c5d40477d3e18cb2a8000b6667efa04b2718fc2329e421
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:794dee9357f6e38c9d8a5e0078a2a4de80c397a107fac27d570396de85b409f3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:179103a7544a1b4ece48abe92c15a574e2a7649c0ab803b59904cb2a1bf8f926
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:73bc3aa2c9a6cb3432d637f8b74ed0e7c1fcaac1d627add1691899781e5d31b2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:f8551d55efc6b61a3b86a83e41c4f2cac436868eb6212a0ccf3c37c667f3264f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:04fc99563dc7ff278e0aeece4c1b99c14c0981e5efaedf8d351eba5fc53dfb1a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:16b88447403d9b78979b7fe92a3f571be7e9e49d315cdd557deb3a80226ef41c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:7cfc599694fe65c721dcac01355a1685fa93df57f0a8c36a50bb7dfd6def3e0b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:e105b43342c5d17432d6c30476f1073790d5701081610f1e33db1076449b92a2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:3432b104ad48152c9ca224b7fb05d452cdb83cbc6135fb8afc06cb4848c42c78
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:31f63db268442fd50523183c230f3f7b949ee8ea595185f7ca17dd35d8b01bb8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:4795c8c6e3a92398dd5609b2ff1c7c96b4db35cf4ec02e9868749a5c85f54aae
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:f889d556ebfe947c3fd3792194cdca3b85bed237cb986086561d4892918b08b9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:83ccbf4347d23c706722cb38357aefaac11fac74f061c1bac4248871a740025a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:0ece1ee4a1a6ff808f62fc19c803f6a01d8620df7c3a60e121a527b9ee8de712
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:aab1256d120b0af13367b837ab6a8cb925fa3ddaf09bc158f7738575e3331344