Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

15-debian-fips-dev, 15-debian13-fips-dev, 15-fips-dev, 15.19-debian-fips-dev, 15.19-debian13-fips-dev, 15.19-fips-dev

Index digest:

sha256:430aeb3af654871e7c24aea16924ba088f79d9cc1b6edca385f8842ec6297b4f

Manifest digest:

sha256:d83cfd248281894c7880065f61073594f31f7adfe80e1e201c1386c521abfa30

Size

140.04 MB

Last pushed

6 hours ago

Vulnerabilities

1
1
0
3
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:15-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:15-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:0958239f85c6780421752439acf6959d455ea3902e32d5556ed3c2cc3036ed37
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:95c5c66b1b945d43d58336e9ee00f911bdb6fd44b5d9f9b52df5efd901d171c6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:3c74539277ac092ba22d77ad560f23d8fb82a508d285ec7a2120ad760c74f3c6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:f2221d3d7bc175e70de25812bea1642abd7e6eea154eb7790d02c895a5519b2f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:9cfdcc018da730acb7f4af90aea90b7994091022fa36abfda6db8ae697325f43
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:301ccffbf9307ed28101c849f35ed3614cae181b6fed19d6295ee799b50d28fb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:4850c18b7bf43f20a2bb6395adda658dc9c6926b1ad40b1390b20d841c7fd4a5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:42c602e270314fe88238d96cf7742709b647958a35f9cefa9b6232c99609c74f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:70dcc4b293a2eef9e57aa34dc60f0137be4c032b478f4d725361464a3b0e2418
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:cf5caa99289d1bb025048ee184c269f5c93f1e67a38286b186a84d306480f091
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:3e5eb236fc82e56e09163f132887167fef6089bd3ad5ce1dfc4239e11f2c7f2e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:081a68566539bb4a45649b74a082c918a20174a39f566791a22b4c201a5c1585
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:6bd04ff1522af9bb1f9fa0c9268cc6f68a41571b38c6506938ecfab235d5660a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:7bef5936e9885de992fe5665c1a73b0c9b480c6e1f180186cf10205663724928
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:8cd89ed1566dc66e9db024209fd034043c35f4fef715d21284b0eecb87e8db1f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:2c484bd02ea35aec3951291b612ca84b473fcfed0b60dc43c1c80f13094767aa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:03b665e8b9a617f736cda28a0cb355f2108bdcfcf1498b2fdcb49516c2fec913