Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.29.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.29-debian-fips, 1.29-debian13-fips, 1.29-fips, 1.29.2-debian-fips, 1.29.2-debian13-fips, 1.29.2-fips

Index digest:

sha256:6a5966c48d7da4eae32dce40b95b0d9c3c86ebd2629aabb97bc6ec86b89e07f2

Manifest digest:

sha256:bde9c61aec5e7fbff4e73f097333af928c351feaa98fa20024118728696921ec

Size

39.33 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.29-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.29-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:36108994da27632d183b1a390d16429b78fbf0846989689c13a9289f96c997cf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:c03d5cebd070b32f789320031bac8096a2ad9d623331ec8328a298425b5bb0d9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:45743ed544dcf4266f476536b685206e3fcfe30d583c0d29753d313bb7d60b71
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:14007ae985485138b3c21741679a9419bf33bbb41251b48df601b0a5321cbfd2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:4aaf51f3637e9fefde8bb983b2c829e091532f2a67cb7c2152a5b5d64f6c9d06
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:cc4f9b20bbc5fd4f1916d89fd60e0b5d047ffbf8f193e85e6313a94776d0fd54
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:1567f09e9c5946fea598471bcea43d73c13e4230ced3c29cf11d79845cf0660c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:6c0edba70cd2a18a080de365298a214278afc5e9d69a644b7df5248a8db3c2e8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:682afaf4257c077e080224e1488aa8854daf6d6d63c30beb20cb601042c8f53f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:6236a1d32a1268bf7cbd56885f75f6f6d6faf63cabad38a88d1c284addecb9d6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:68e08886fde1a2f1663561afafe515433e4a6eb985d2db5b85b54abb7a7bb595
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:dd0bfe2dd180931014567066dd6d883ac72ea74463967312e020e14824fa6139
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:12504120360af8fa690cfb6054ce63d18ccff1fbcaeda3f52a5b6bc0c8890473
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:5fcdea2147940cdd019d1d24d9530c2a9bd5fd921070fbbef57bcc2c75a3df0e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:27ce341186270ed2e7a789a0b7f5affd6bd2aac1ec30a1bd845d41aa68ccdc4e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:4d22e017b93e522551b7d7886b214678fa98cb680de7ba7495849694c37a0099
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:5036de8338178d92dc8cdb3c931f01bb726bc5e54b34735243f1e125342981bb