Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips, 18-debian13-fips, 18-fips, 18.6-debian-fips, 18.6-debian13-fips, 18.6-fips

Index digest:

sha256:64be2c1e55919c122bb914ab19b5d57c328051432c4166fa994d4c0d0b06c7c2

Manifest digest:

sha256:78270bffe9ba1bde732b501d39cd0638610d983b9cdb31335041d7b7ab97c1bb

Size

132.05 MB

Last pushed

1 day ago

Vulnerabilities

1
1
0
3
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:615b9d32277ddbcbd11fb4ec4cd8a22de19983dd2417d6b3badfb1c5c1c47bd9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:b5aef8feec5607de946e7a760cde42738afd73c027071d0451f640f2450e1288
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:834ce600f9e55b8aea92033c7ace19f133174a72cc89ee37ac7b281296303166
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:ff3842b4f9731e1b926135e641512b1a24d912921a6d499b3a0dfa371d8da554
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:9c2c3c6c522bddc2280d6a5b91372519b8d0f7594e1fa8fec7094c712eac13b8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:a42a0ef2debc0e28727356d36914c4b23729baf546ab1debe10be7327ea5971b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:9fcbceea5ddb620789af74ba8d6e0b2e6b02909b1ed5a4e60628fa04213a90ff
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:0261349a9e16b39f27c18cdcada740e1c5f63406a9877a56b9ef91e486b36bde
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:700614bbd5b07f7dd8009f384f4399a326bfde96dd2b1e5c3c167d02157476f2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:1025fb6fb4a2d6d2b2657647d28ac6bc15ef12cb8d3e9ef961308683c8fa2042
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:6eb81b7dc696148e6e0a6274e5ba9e8a0fcad8c2b9de2618dfd0f6a6be64ae89
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:ef2a222cd2d39a3bf7e17109eddf7d681ed3b7ac1ffc26e5036330e33247e9e1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:9b198c01e873f678299f51cfbc21f48ab30a5ff23e2983ffa89490ee6492d7a7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:fb9258baface66d1691e529e9f2e9de6e8de7c81c344f9ef97841f1d166e559a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:903cbba0cf93e51ab089351de11292ed6915c22bd4d09323de027f1988475d18
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:0a8b811b575c9718de2a6979c99f9e7356ba6f2fc3c0d1f9730d01507f88a3d7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:ae8cb27f4a1975db44f58d2b05df2301b809e8454165c3dfebf1a6d4eabd8830