Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 17.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

17-debian-fips-dev, 17-debian13-fips-dev, 17-fips-dev, 17.11-debian-fips-dev, 17.11-debian13-fips-dev, 17.11-fips-dev

Index digest:

sha256:9c1cba90a10bf7f2cecd54513c867c53832bc3b4f47d24f0f6c2009e71ee3167

Manifest digest:

sha256:fc567d2664bbeade37f75cff9af3a91996fbb9d3855baef45979aca9859a4da4

Size

141.39 MB

Last pushed

15 hours ago

Vulnerabilities

1
1
0
3
0

Support

Active until Nov 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:17-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:17-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:bd1a3dcaaefa339a5880ad8a2155f5de957f765274febafb1656a7b90b1bf035
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:7b63dab0a50ae91cf1e1df86cd628bb69727470664b52ab75a92e1dbc665d8d9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:89110a8f0661682b8787f36054f2caadb4fb829e0ebbbfcc776f8b7bdd100445
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:de08f2b6ea89988d9bfc44d013f26649098a3414d854f58e257726faa2472d2f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:02775b7529ecf138b807daa6ba9516441b71233f74145a1c6b4b07956f9922f2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:ed86cdf987bf036492704f31487eed1fc5d14b52f1ea84b70a5f367e9d1f9d47
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:844f5de197d5f9d2dee37295ff41663d31561035ec5a1d33f241ffbb5909c0b9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:e57692c19ce7916c3a0262a0f704f55b67dcb36bfacf2c1fb5be10aadd359a82
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:8af54dde0e738c0bb29890c7541fc385618a7fe576ac138e858416b79e464148
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:b8eba5f7187144fe0ec6ea095f8a66061120db301331db8ccbd866d76ab80714
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:2feb3f0d5a024620ffa12829a02fb424cd57b652a936ca2f645b2e9eb5892fbb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:2dd23c8631937d64917704645773786821dd162ebc2165b71a8ac42e420f9d83
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:319124523c221d6f00a543b35d0140102ae5ce8fc12328fea5009ba0f2ec5f0f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:8029395f451463a1de46377946b18cb6083b2625f5d14b7ca935b9a88981d7fb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:05de6aece2969dad3d4d8660cb74baf1e5d3a9b0cdd46ab72f10e3c9c3c7de30
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:46bc28aadb6c50a0d7a70013c83f4309df5eefd1f4b1570e30a6f9372c3f5bcc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:dd436e79d91985e6c8e6b58fcf95de2faf7cc231216d35a0c1f46269411e4106