Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.29.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.29-debian-fips, 1.29-debian13-fips, 1.29-fips, 1.29.2-debian-fips, 1.29.2-debian13-fips, 1.29.2-fips

Index digest:

sha256:ddaf9124fed556116c8d58e64bb889abd1a1df41c7ddbaeafc0937c3ac28e72a

Manifest digest:

sha256:0a1b459f6a4304fc4d16d591da1f752a4c82bdbee34d080dfb6ee13c221854d7

Size

39.33 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.29-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.29-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:13ec95e0f815cdf6cf7f3d92d593ee2a764bae1e9b5b21fc4746481af01d4ff5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:00e75a56e9fb60a36781766c8e26ca0704169c926331fec3328780fcaf4fbffb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:012e4ee2528d3889eacfda83c6fbdb505d082947736611a26320926b10ac2cb1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:c50686918178636cf33cbc8d3132adb51c2c17a03bf049a748f5c33ed35116ab
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:1c6b9472b4ec2250abe8065d20f0de80e560b1d281cbdf1d7293a7955fa78277
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:e954caa3454a1788a1557865ef50b98fd082e97756ba516d911ddf61c2e8f450
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:6908a9b01820bf400352f270d06356861c0c8767c67cdb912a49471c1a4c6ec8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:df277b157eeb430fd28e92afd28462290763f7556d0ccb703ed960bcf3be2422
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:42250546b17a286466c5df98561f0c48dc2dde943f0f6d19d70f5a1edb6029b5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:e50a072d2a904a3d68c43be141f889254f09f79f050437f7ad7230ce9beedeaa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:61c9c75f621d0248dff26b33ab54a559a204775d1e169f0f79952da544b042ae
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:240e16854db8c5e8eaf2315652b17b015d409700cbdfdc322a8506b48ebd27d5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:c61ea702a28b04f21ea2d93cd027951bfaa7c876fd281ac9e323c4b53c3bccfc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:433203bea690026c26ddb0eb119fa894871bc75663e6a7207d4a175f3eaf44da
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:e09512a6515de06867e3ec9b686326d2d3d54bec89e71c1b1094500028030d48
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:8ad000dc38c8f3b4e498991a96c9bb3b332deb204c747ef669bf4e4b59a2a855
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:151ff3c3722e499ea092b9d9095c0567b60f6a30cec34c7a4e171c996d5a665c