Sign inSign up
Patroni

dhi.io/patroni

Patroni 4.x (pg18, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-pg18-fips-dev, 4-debian13-pg18-fips-dev, 4-pg18-fips-dev, 4.1-debian-pg18-fips-dev, 4.1-debian13-pg18-fips-dev, 4.1-pg18-fips-dev, 4.1.5-debian-pg18-fips-dev, 4.1.5-debian13-pg18-fips-dev, 4.1.5-pg18-fips-dev

Index digest:

sha256:47a1a8d90662e900e85a42f33108ffa3fe5bede03e8fd8dcc6e53411580d531d

Manifest digest:

sha256:dab43de9a20dc33454bfbc8e302b5417328c73475cc4fb8dd91162b687233146

Size

179.97 MB

Last pushed

4 hours ago

Vulnerabilities

1
7
7
19
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/patroni:4-debian-pg18-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/patroni:4-debian-pg18-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/patroni@sha256:7a8f92b53eeb83751271df4432d3f51e783affeca07358a0925472a28a15cc9d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/patroni@sha256:c6fbde1d2122e528d88975745c61257f69f29475b2a53b853ff82805c84d2d6b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/patroni@sha256:ce0944b8558e4d6143653685b1447af02c2338a1fcf049e33c9d0d8c7394ea18
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/patroni@sha256:f6bcbe059083980d1ac83a7f538e2215750d45185080c94bf7cb484a18256be7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/patroni@sha256:bb0bf1639899ede42ff0cb0713af49eb4f4b50d32cfd8c563358daad29ec3aaa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/patroni@sha256:58bb39cfbaa422f1bb1ba034d258838bbdb006b7ccb01773fae4942b54e8c9e5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/patroni@sha256:816bfbdfdbb96644621a9bbe14e0b3394cab5be999ffebf72f45e3a0c65c2486
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/patroni@sha256:02e654aeee51a7db7952a0319b0285bb4207a08d6f2c2d018586a32d325e99d1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/patroni@sha256:4f984e29639cb6553be69789943fadeac52629c744907a896c84e221c9075fa8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/patroni@sha256:ec925d13f63d9df8d6c76745303b792b2c57031ff5078b2c68a4a920602a9e5c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/patroni@sha256:fa00e2c4e863e9024b985664b9654c22e4fedf533305d113bc5f229bdc1ced37
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/patroni@sha256:bf0183f0181d5db86c455b7bbf0792b5c51444fe066f935729c533a93f45831f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/patroni@sha256:c1dc7796e7a0aea9791c637cd56dcfabbe1663ca3490b146e09664d5ff91a6d3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/patroni@sha256:d1c9b3076a8d797ddcdc93063071bb53989769d34e2c16e0dc2bcad4b0d91363
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/patroni@sha256:c6b61d1251101e9ff07185f803e9a1c5368b60c110fff2f8a577b0e4086cc780
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/patroni@sha256:3dafeed151bedeeba871b3c70f68c0b9ef68b886c9e7476d4c1becf059f18478
SPDX SBOMhttps://spdx.dev/Documentdhi.io/patroni@sha256:05a692350c063bc5fdbbdd0cbd953325013f47aae1635029b31638155bd47945