Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.30.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.30-debian-fips, 1.30-debian13-fips, 1.30-fips, 1.30.1-debian-fips, 1.30.1-debian13-fips, 1.30.1-fips

Index digest:

sha256:9680aeec4d88664ed9a332f5a6193a7625eed5bb76355a87a476a7881707f439

Manifest digest:

sha256:fb522d50f58b490230877a2a7236fbe165aea35eeed7e554068dfe62311d5d1d

Size

40.34 MB

Last pushed

1 day ago

Vulnerabilities

2
8
0
0
3

Support

Ends Sep 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:2640983a661e5a0ae4924d76e5e48a58ec7fef59fe6ba6ce8f284a796048266f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:c5b5dc6b526302aaf097b37698cb74603013c22fc7487952932a2212ed7e7f52
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:344ad8373463758658b65d377b3e184b62a6b457c4e0a79284c4074c9615f311
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:33f4ab778f161fbd34be7f72eea7c53ce450a94bab0c3fae549de2fe840e9414
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:56fadbed6df865752369fca5828192d63b6ca8469ee66e1ad258e5760f0e6c2a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:a65bdad24c22814d4b85d7084527443cb6db643250aca98a69dbf2af99e1ad38
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:d244f9725cc1e2e8e4af96b9eef3fda143b6697710d6136bab603e220fb1405f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:a287371648fb82d5d11750edaaeafb5a05ee21145863b9518654da3cb6a17d6d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:e451ad40313d32485e3390ec91f41ea949238e7ce0a55a0c89761f8913d41c4c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:1b6ab0ff14ec07ff763e8ab476b5d5f2de81531913c8b1f31dfbe77d59a341a5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:9c00f8d88b31f223df75310058c7ba4062b55f1bcef695d5e457ac99f6f8c1ad
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:52bff06b67449d23e5d361b47e1ba27195e543f9a7f3ebb7750b482d5643c9d6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:4d5227f5b8507507c3caefcdb47906dd7fe909b4d3669854166994d1a4e952f0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:28b69693d3f1ed1dc4f262f557cf511cd1301f143f9ea3e5aad70cee1529b543
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:7ace6e7434f7bb5eed166f28cd148ac9c9c82499db03e4c7ecc5dc6494eb24fb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:73e1151609c913030f3dbfe4239416990c04064b9c9757cd52a0ecacc3c32e09
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:d6ae5b58739af0872f6ac8ddd5a1395aa001c7b716c2b3cea650850eb2b6a6d1