Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.30.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.30-debian-fips, 1.30-debian13-fips, 1.30-fips, 1.30.0-debian-fips, 1.30.0-debian13-fips, 1.30.0-fips

Index digest:

sha256:48b7520dca7cb9126d0e107246420f1018a124aadcc75f7837608d1ad1c8ef09

Manifest digest:

sha256:7915648c2924905ae6a5e67767a70b843bb98a19e02d0ee60004f042cffc7985

Size

39.46 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:e64e257724627ee207c877f46d2898d876db7ca7c5a042e431954620080e287f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:f36ae91116a997b8972e8e3a85a212cdd68706588b079a1e073127ea4a864801
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:6fceae4ece335d484848ece50028281b632eb4fd05e193ac5bf28f016510e625
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:36aec46b28c68b3606248ad2fb80c865a52832151a556bdcaa12f6427ef66b94
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:01376fb5fa703261cf0085c62014955b163b3ebe927755c0ad4f8423d464048b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:a6955b1ffc3f93f2a25c5d0ae7a513c348eae141d8bca19701c439ea4782acd8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:e06366bb6597fd4397a7eed2e930c97cb33c7c71585ef518acaa4da1c8231c88
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:9407e10e6e970156dd78bef24bdf2fb818a281d76fc4e0fd719fe04b6a8b621e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:89a75fb4383d8ffdfe52dfeb9cbabc4e5e7f932f57699d8cccedbd275f64c271
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:014bf419f543e21d092a201b4cd2ed8bffb94a8c36a581b6cf88ea6f71b9e1e8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:00184390294b5d326a6547569e5e187d58c8b2e5f8431154e91ad173d6bbfb1e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:6ef468f213da8ed637e838e67f2b36bb91b619164275ee5fe3fc697c27a08a77
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:febf8e82889f5103ee8a8de45fb07f8fe2a107b0e091bf870fa12426ced9dd82
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:b01988f539ebce263a88bcc902e89143097111cfbf9b5b56a479dee1f6a2429f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:e4fedabeab3ab04b4824d1b0a1b23a8cc7106cb09a08d4abf82b0d0f1dc65e8b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:4189974de4334abeda9d9a96c3781ca6e83cf6d0c7900342f01fec15335fc569
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:c98b096b4719dee7cd213d1933f07f9a376a169a988987a166334d97b2f4ebad