Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.28.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.28-debian-fips-dev, 1.28-debian13-fips-dev, 1.28-fips-dev, 1.28.4-debian-fips-dev, 1.28.4-debian13-fips-dev, 1.28.4-fips-dev

Index digest:

sha256:a4de655550bdaeb7e98c5f60424b9cede36b6f42ae8389482743ffd8547127a7

Manifest digest:

sha256:12c0239ada196fb9f511ebef25e81f86566ec507d71996b230ad56ca66f6a744

Size

85.49 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
0

Support

Ends Jun 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.28-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.28-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:08bad61e6e5fb8aeb1753d9caf977a6e9639cbc8dab047c0f4b927798ffc571f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:f870a0513ec2193173f48cb208d1527dd0598d707ccf970df13576273be9cce2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:246367078b6e9804d3cd2d8b4e6ebde01acce6883c67e5037c58653ab35d205e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:30a7edc438b683b0da50945f1590f1251eabdc1c16f617df3ae7e28a68cf46d3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:7d6194cdb713817b52f7d067c00e33bd666580b477c8bf0f55c6e060a95ddd18
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:abb7f09c47f3ccbfc6f408fc11ef94179f3e3c13310866de184e124b52cf2f10
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:d20e206b8e4b3209c6a0d621a93aa1c9704466d2adb1d8ea06855fe15f55811b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:7e08b6542d6b5c28f3017a9c775576e816a820b914f395eb7d56ed766e0daf30
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:8fd1890e431eecfaa72f853369e875f624d2c25fd96d59681992719352e1d1ee
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:e89e80be19d05429f66031bffe1dd3b57563b99362e4b838f05baae6aa1975f5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:bd8453d5dc92ca0755a339ac826426cd2eecd134baddca237540c2c72f6517ef
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:290deb773fb8f2f71d1d73cd7104cfee29884a858d98c1b262cab72381790b29
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:a0ca88fa53fa2eb8ae101a4ea2761601764837eefa6ba102addab602b2067e88
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:a528c9965295dde990839e0e555673b4b129a332cc8921ab33d9fedb18c1a308
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:6b7345405870ba86b0fecefb99c96d989073c29ae876794f0825ba8ac8dd9f41
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:5f01b2def299e58130dfaaf426b2451ef2b566e4f3fe989d5d2552c32da4abda
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:e2a8b4243bd9cadfdf2e56c3745117448ccc22aef57783f9392d20a3df2d7f88