Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.6-debian-fips-dev, 18.6-debian13-fips-dev, 18.6-fips-dev

Index digest:

sha256:043c7c900d44fc570f7b5592bd362f510f1bd7c134c856a8bb551b846d883ef5

Manifest digest:

sha256:810efad60a02c5ae9523128f85002b34c6299c51006a0f38d94ce86fbd82874c

Size

142.09 MB

Last pushed

1 hour ago

Vulnerabilities

1
1
0
3
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:2303b159d347b5b1b31557f880e3920172f12273424ac5d55be516b7c6df8b0e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:75f61f1572b12d295c09f283ab4d6c2586054577df9c0174695800b2df6ce2b6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:d87b7655696e5768d686649b9b9f85b28d9ad92e1e8bb80a35a4f21153c8c2e0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:dffbb9c9386d203c40d9665b2a1272d905671764e0532e3e3eccbd154aea866f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:2624cd564c09373e1412d01a7fa7ce0b6c46d0c537d5961182d5beea74c48798
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:0963f890c5986a6dc37784ed7701fe0383b9575fec0c5671a24398f9eb830fdb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:2dbb45c48dc280b5d63cf0093329e67150f26dff424b9b733ed3aa8afc8713d8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:63ca9ee8833e18132761a403a9ca3b07141d0bd7c490af1b6a92475de9c50cfc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:4a188797e0dc7e78f5f3c759debb5548e6c26c965f5fde5ab5c4eaa984ed375f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:6ba4171ab2b772e1e240bf2214bc36cd80161336e0b3d643c2e09946b75f5b5d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:2c75b688467f8c8d7491487f062d77e9d885c1f3bd864508b711ebfa3f6fbea4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:f446224bbc7139ddf2eac553e76fe08724887b5e64187f6aae576dd4c13579c5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:dca89a0b0a91d67d75433d1820574b205844eb9ebd3edc131beea3948fa034da
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:22d3864e1f4faf4796a03780d15adb17421fcbade50a299f18cc777763c5d273
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:b68a06a5d95ebcbbe146273fb495a4857545e3e06a52cf92aa7cae5eb537d10e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:8d08eb32df480084b1d52c5c038ec52182d57f8a5b36e4858d2b1ea2ed19f1f0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:adcd5a1ecf5f98a494c8aa3949ae34f23daa8b32a9eadbc80d4a834512952d84