Sign inSign up
CloudNativePG

dhi.io/cloudnative-pg

CloudNativePG 1.27.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.27-debian-fips, 1.27-debian13-fips, 1.27-fips, 1.27.4-debian-fips, 1.27.4-debian13-fips, 1.27.4-fips

Index digest:

sha256:66c1b3b7b05a142c75f5eff3842fd33275912e56d5a8038b494e2819177e4067

Manifest digest:

sha256:39a89954c27a6541e23ca75b80f69ebe8eb93c9f8400b48c1e795a2a485c831f

Size

38.80 MB

Last pushed

1 day ago

Vulnerabilities

1
0
0
0
0

Support

Ends Mar 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloudnative-pg:1.27-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloudnative-pg:1.27-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloudnative-pg@sha256:9770dc6ba18ba054ae3e0981a62e13a59aa63dfbbe502f6f050baa064c5d2a82
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloudnative-pg@sha256:b1a53306351a0d6c4fdce3fb73a329fe213edeb9869647b212f822165657326b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloudnative-pg@sha256:4816487ff808795086758b54037208e6d998ceee0cd86a4b5aa91552578bafca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloudnative-pg@sha256:dd2551bc0e03963bf4a4ab674b42e46c69921d6463e495fc135e055984f38d15
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloudnative-pg@sha256:cd99a0c1f0a466d301001a98506c048295c6a1f87520333d5f2a64a7410239e0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloudnative-pg@sha256:5ff55f58a14ad10021de7c999078ad5497f11b4a62f45db8b48219740b043084
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloudnative-pg@sha256:ecc8d2296f853cb6d93aa7c9d7f51f4bb79adb2b04e05446a7a7bb11acb522cc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloudnative-pg@sha256:45921fed1c799487ddef1085b246085d058fe705635810e9f6480b5182a2675e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloudnative-pg@sha256:e65936526ffa8a9a573dc259bef0966c213cb0edc53411a9ac33c5b115f5b883
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloudnative-pg@sha256:86b5d438cf6d6a29ad05dbe32a384fe6c6c3be2c9dc9c0195281465342918b4d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloudnative-pg@sha256:9b8942b3224b27f9c93f00a701e1ce6d58c0e9dfb53cec95622b129292b7b608
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloudnative-pg@sha256:103f5707d0552ca9320264bda48898afb15afd35581d6431e054d68224a8d1b7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloudnative-pg@sha256:d15b54d888ff12aa37de2fa1f356501119156852e642810c6c5368700d0c4d8f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloudnative-pg@sha256:f864241d00e3e313a552ec73bb798a42a1c8f93e3da9616e599e59e36d206a5b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloudnative-pg@sha256:8f1cd06d3ec551b6974b5f3c39676217aeb93fdb5e88117a7e050a5464b6e7b5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloudnative-pg@sha256:6fcc4c80c526a8f585b07e40d2e045cd0f055d16ee6047c964a8e1d1fc993114
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloudnative-pg@sha256:43cd37fc831b4953587d74bf4dcc9641b235f4ba258b6cade44d1a620d877c40