Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.27.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.27-debian-fips-dev, 1.27-debian13-fips-dev, 1.27-fips-dev, 1.27.4-debian-fips-dev, 1.27.4-debian13-fips-dev, 1.27.4-fips-dev

Index digest:

sha256:326e6383f5442da874b38905b20dec0447fb9c5c39334c5eb5e50108139178dd

Manifest digest:

sha256:80641d24fe1f3f3eff9ea7742da8aeca314e7d47d48d430d6f21a83847c30cbe

Size

84.92 MB

Last pushed

2 hours ago

Vulnerabilities

1
0
0
1
0

Support

Ends Mar 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:d197726d25bcd03f88d5ec30570594399ec7db72aa2b4076c0367a20b808b805
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:8eb11371d3a7f2d0760d5611deba74f58ed251c23dd91fa37fe87fa72a79a045
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:4a31b14aa43f3c5102448f4f079dd772431d1d43f533d6edded17438d4bb0741
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:24b203af7f9c730a53d348623f4557e6b33b125588db39e4f6b6f764bf69fed7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:a583638c888566175ee5779eb788fd95c8a8ceb504e85484bd1ed412d8dde94d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:c9473c7e439f7f2703d520a696df218b444758e2076bf399fa0e9c255ec471fd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:89234331626c1f9b8aea6c77c18962ebe2a5851e6c5745a6009fcc8c68c00a87
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:a16d8a3155a55010b081ee3bddee7c1795699ca5abb41430f5bc767767ed6d28
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:f31bd2cf6b61bd4fd3c09c66852409ab21bfb82ca73ae1a028cb7de99767b993
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:794c3763911b68ee225c1555f6bc768c1b7b382530713d8b978dd1f2660ef750
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:6142fdf4b8d3b00bacf2fed76927fd939c474859f986552bc59e92d51d92ecd5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:1f72a76ee3d03315ba35f285a2d05f964067615636ba552fc2a984ed9c1ad679
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:e29bd099eeee45573912bf7074a18a14fe1f187bc6cfcdc0968c154d1e5d943d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:df8c15f3cfaef41a80a7f5efaaf88dd7b23446fa7bad9b5a4d14d28f3809f625
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:8fa65f8ef8276fb8fac14841e69dd97dfdff05ccc804a16069c15f9aad235dd8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:59c856a9e906da0ff4254860b7b32f525e1ec6ac1f221ec0fc92430dc1973a37
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:1ae5238abdd7dafe91bc3e0e6515a1b9e87176b9b2f0d21dc043e218f3b5dffb