Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 17.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

17-debian-fips-dev, 17-debian13-fips-dev, 17-fips-dev, 17.11-debian-fips-dev, 17.11-debian13-fips-dev, 17.11-fips-dev

Index digest:

sha256:dc4690746401dbcad6b1509235570fbf3f4d409df6aff164fddfa21c39c244d1

Manifest digest:

sha256:cd3f9db1014c17391862995c54385ced8f5c1e497cf32a8696275fd1813e7a66

Size

141.53 MB

Last pushed

12 hours ago

Vulnerabilities

1
1
0
2
0

Support

Active until Nov 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:17-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:17-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:8962e7177d233b1e780d452a64cc295899e414d4b21af822eed5acd703bdcd46
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:1a9ae8a107c08355e060d5524688945c7cace6c078d2554980e108d5af41f13e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:10019ca17c8c8948acce8e1bd2ebb2f29eec680d0baad02783e9c3f22d8c0db4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:2e35d361beb539310c1b109fe9bdbabeea09dad66576604164626716142ec167
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:08fa6be7b7f4242280ed431a44d789140eed638dbe377cc993e6dfe85d9abf95
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:397e60d08be0665bcb2550fbeddbe900f588338c5038f1d1bbbf4f38578fb729
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:9d8b56ca454b03c0b711cf2094c99f64f774de59823d52a9a34b3567e17b50d8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:2b3dcf538597a2ec813b8381438765e8a8b37343d28aa8c979c706bbd5304921
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:987a4421949304f81950c5f952e558ea15a126f3c971d0fa317996dd61c1b5c6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:660e5b95806fef6050a80dd8df413c27f8bd3ce9d1a19cdbbff3e6803f1b3701
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:24c13adba2c33c1ac0ba51823c6fae063edbdf01b1271fc8b02579392667d10a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:ad12b101dd1d692245c12d1dd449fdef099e61bb4a454b7d0af434fdb3e73876
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:b189ebea5c3e02fedb31b6d8fe093fba3d869beead92aea2efa9e3fec76ac61d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:92e5eee166a486a72ee45227a23335b87fe2ecd4cd77c22bf60826f70959c381
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:3229f21eb1205dbc65c04d5d8f1999a4cbdf5c1bda8ce07bbe36c6e2d59e490d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:b8db8ec2577501e500285100d7724b6a1f894e9f1c325d8bc5021536d51c3598
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:b53bf01d57d18e3de47ddbde68a92e2a7422b0d3c6d6e8dfed44af70856fb31a