Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips, 18-debian13-fips, 18-fips, 18.6-debian-fips, 18.6-debian13-fips, 18.6-fips

Index digest:

sha256:16cc8b411872ec711316527ec59577bf7d9fa47fbe92907df7a4d73f8315e4df

Manifest digest:

sha256:6e49ae195867ef0691c9cae1238469ba0722f7410a553ae14886925fd42352ab

Size

132.05 MB

Last pushed

15 hours ago

Vulnerabilities

1
1
0
2
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:9518f992b8bc471b612dda8538fadad10fc9869b215d3a7c5a1f158fc186c266
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:2396593bd743427cd4afbe871f0a7a3ae149c77d52e3c309272a6327e48649e9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:09af1d96ced338e6cad90ec3731bafa330ca5b3b3a1c7818857ff4e4a23cef1c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:0bccd92dcddc1f528960218f8e9784f5934e66c9d2898cae0a9c7fec17039539
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:22c094748cfd315001cd330378b144577a5b8fb79153baa5db105bc9b4287df9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:f9c35c602ec11cace7a75be647a89d9a72d9a204b119415bc45645b751a6eadc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:0821a3569623a914a04d98ea580a18e4afbb5b3c4c7be8a7f1dcdb94ee794bf2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:ce09ac19609cb2fe1130256f99def9b0634cd4d70c45359f1b1eb6d4449ba626
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:788c1ef3e76b4dfeeab6875dbab0d4d30a72c1807fc8f88680579b3198fb73e5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:881bcdfcda09648d06bcb70e95f694e5aaafe5cef97355118db137d8edf7b6cc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:5d4a2d3b25e868a841a429470799d3695e0cd70f050aef1f88c6c3077873360d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:69b72731064cfe5110162fd0c800ebfad4a14cfdc509a6c19501b4f472ad89dd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:b0a6be3c903cca5524061fd01e74df684d71ab06d5bc09723a7719cfa4b2d3da
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:675993e3162b74fabb84f742a342227b5dbeb11eee61a5cff1978ce15029081a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:712e91ed1cd37c8e01a7b9f6bf5a4f8d0ddade67a89615b753f0553034ac3e81
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:e1fb9a7ea615f155a45fe09346e70ee906a424c825c3642ab3f3093dc7f1ed90
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:3288e513f9058a8ac2ec27618babac66a8e6e67e6f0596c9bb7acb6331a7bffe