Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.27.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.27-debian-fips, 1.27-debian13-fips, 1.27-fips, 1.27.4-debian-fips, 1.27.4-debian13-fips, 1.27.4-fips

Index digest:

sha256:d4936439e86ba7f4abf3296e68ca89ab6ac7899d496a8034c2d54e89d80559b3

Manifest digest:

sha256:24bf585eda4792762a0923038563c2270a32b3d15db2c511c4701e3501e80859

Size

38.79 MB

Last pushed

2 days ago

Vulnerabilities

1
0
0
0
0

Support

Ends Mar 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:d11df8026703f4c1d2de02379a88986b2678721f7ff0d57f43c8a69db47fc719
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:43406b059f50430002f24617878d17c4a44526468520459e08ccd225624fb484
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:1e60fda34b361d903c60c04b13143435a933a075c557e2a4d5a7fd9126f94423
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:21da183b86a8e4039eb84501b45335388c1027111547f94f098491425ca11406
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:17055051b5dd28a35b61171e287328384ad92dfb2649d563ed7857e2b94710a4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:73736a59694b089bb09f66c11cfb01ce9d6b588f7ffc9db1d49d4052b09e9823
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:94a423bfef6f82ef501f516bf60538940d0526708611e1b2a18f3604ea32d64c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:b6affcef343090e312a1d6de49f6a1cbd3911f10b412c8df83e61e5440a9ba4b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:12d5fa6bfa69226805bfe1f17cdb7a6ac3e99281bf8cffdd215e875aedd88a50
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:1b27acb680196a1e3ecfdc0c62ed32ff7f66d67b3e74482ccfa880f81f00dc2d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:de71737f17316441d600f3bc08a722cf02ed8a1ece87ef2033d81c75d7f6a467
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:c3c8d54b1d4a76a31a4d9f3c6f0f659bbda7e8e5752e6829ce2c4c1d52682655
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:416d1c7f8ac8f3ac9f62d41cfa26b0ce463d9a4c582330ecf3f87ca4fc28a8a3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:9ea4514489e90014abb2c3ab42eb804d10aa96e7ed6a792d8b5d35badab55109
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:63497d1e81e8c36104461f12066e861e0426e640be86b8298e3f616976495856
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:7a3690fa1a7e4dcde59a2ceb0ff59bd917f93d6e16b896615c47de0b510ad42c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:bf407e079f3f35f4362beb2502343b91b3a5d8c9f051cd129e6348a6424cebee