Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.28.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.28-debian-fips, 1.28-debian13-fips, 1.28-fips, 1.28.4-debian-fips, 1.28.4-debian13-fips, 1.28.4-fips

Index digest:

sha256:03798b0a5f1d7ba7806bc4769bf8ce0bb279a1f8878615f5777f0d561019106e

Manifest digest:

sha256:9a708ef2fb4d48d3794bd5bdf3c46e663a24d2a01f7885765ddb1cfbc152ef97

Size

39.16 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Ends Jun 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.28-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.28-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:b004817b6b6b2e2ba97ea110a8b1aab1c9ee0cdaadf13bfd6afc6a744304467a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:fe79c1d33650b2a3ad287a96a0515e9828ab6e5a34f0feb6a8618329a63c4dbc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:f6e7ed4cbb102d4ff1a51bae725d5c5a3cd29b99d0c83ef8d17cfd9eaaa96239
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:25f161a0d8aa9df0274cc7014f84f443f2ae4092eec3ea2ba033f9b33d9c5fb0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:2805262236b05bdf5e0cbfcb846f7fd194346dab3361e6202cff74efb97454a7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:4c77d8376d58188d2c447a203d03c91a48aea6f859c806219e20155a51dae55c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:d9faccbe3e0a027b14deb72922d50ed81b286e801a4dffdf4b7d4ab8f7670566
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:42856719a640e32452b7cb2d60ccd507a8bfef9773209259fd17b8ae45a5be19
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:8da6af80877e9812970645f1ee92d5bd0de9c4f6a16b7c97e3ade34aca4f9b5d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:200cebe02740fae454682393d3dfb4f1b6acf9b1fc6ed649d9c6e73d6c9937ed
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:096df5162b5afc18c79bd6897c39fcd5324e9f5ae9aedbd6021e94df8c7da08c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:937c4b724634494c8b8147b71caf730ddb8abacb445ebf8e4842e5869d069613
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:6031b16192864588981cbaf306958bb25394e4464a29d3ac3cc5abdef82ef892
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:fc3662e7486cbfd7e25b28e4e4960e0ea5d35235ea060bb76f5d4b38555bb571
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:01e5e04ff3e67f2f292c873103521c305f6701ec7add3f8ec94517ebc1949f01
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:ed68261d86228429f0ead64d8a829754965a80f6215e1d7351a4f7b85d92e1ef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:24025a86e4f4942c504c6ac34fac528b64550413cce5746b233e5cb9e9413f43