Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips, 18-debian13-fips, 18-fips, 18.6-debian-fips, 18.6-debian13-fips, 18.6-fips

Index digest:

sha256:3403071026533af73aaccdcc870665de1930bf6f401c4565f1b45641e3a3672f

Manifest digest:

sha256:3d041c53ff4aa4951c2cd5dd3065382fa26c67c7abaefe4c94b7d262a6d006a2

Size

132.04 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
8
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:7de967840594b811847966b2a0b514fb7d88ea38cc8f0b1d658ff7f25f8f9421
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:422ce869651f41f5404bea04dc26236229ba6d196df7de8a1a5d5623958cfb37
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:e715447bf97a3d118c439bf145cd738fa3ad215481192c0c40f2fe18f0f52fb2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:cb0c944d27064429bca298597667467239da845c71a34f848d14a989b7d6c500
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:28e082afec89dfa028be17d462bd6aae3321b12af5285e318247848f5f3e178e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:927b050f841a5e9ebc6de3c3eac1cad31b0558428ec8d7b783dadd57fd5e8c7f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:291632cf0a38e88a4d16d71e564099a8a0ca3ebdb104de474b915b3f28a3b6ca
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:8c283d6a29495c292614a5967e661d9fa160a1ff601cf9b19b3c8408b69b6977
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:a58e57a85db12ee59a3bf829032b0804022fd0901bcc68c1539df3c85672a73e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:eaed1078c23ad862721bea368f923d392c46adf74406cd18cb8b480faf0dc2bc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:11d8a95a6ca68aaf9c69a894ee1fa35333c9e1cf4d14a99484af94a0b41bd806
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:4c627d458187738e97b72eb554b926f8fa73d6e691c22b34ab26b4efc4e37795
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:e724535945ef4a2bff127422751c1eca4dfd49ed66a851304d781bc7d943f941
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:747119b5228e5daf41cfd7915168e5a77b8fa567696935bb3c7da1b7d6a2fa71
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:76159f0cdca3f24371b671283829d3668eff87633dc364dc076d45b7f3367678
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:4aabe31e2b63040cbb15882469f81ccb93b98dd9d46d1a8312a413ad9bfb3b05
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:39c8c323f95edd139c72a9554e73b4519fcf1d1d19135d7885e2b2318d4d192b