Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 15.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

15-alpine3.23-dev, 15.19-alpine3.23-dev

Index digest:

sha256:0a8fc829530883da12b2056377a0f55c09a1fd3b839b9ed42fa2c321ff91e191

Manifest digest:

sha256:cdc177ef160eae8173d3b687fea9bdadb028c01586b04d60f87ed4064ee07ef0

Size

133.24 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:15-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:15-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:d5023d8dda0560a9fafd7ddb90b006e1c8f776b77e334d08a997c5d474b252ec
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:480544ebd0edd75f17c4a5f8612cdd1597050e8bf1a48d60acc6eaa39b9d7f9b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:4e95784820b71435128ddbd9541886e25fc00e69d2d74318782a207c0d168b4d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:ce784a18c2d5a465382bb8a09a0f8e6eba769b5ea64f2041b7dc6743da079bf6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:8c1d41a3f652e2385131899a0cabdc220535e6994f70fef4c4275c3f56f02ba2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:ab21f8539fae2baeb5d91dbe3f9fd71df2959c01e564f50fbc0874a79fda3e0c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:a0cf3b5dca6d4efa6ca65bba7a5a9d177f65614d9bbde349867dd181332018fd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:c0a4c3cc10f4cfd34a2761bbd6be10b585ebbaad6674a18833aa65790c381e4a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:66780ff1c0980ad49c76e46f583ce5a5f5bdf84c840ee84cf93338c11291df98
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:c531fb4df8afb9080020e80690514952240f88cbffb71fb798f314459918c5ff
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:621701290eaf04bf2c0834dbcbd04c2b61f2c0cfed2e6dc60aa46faf453a86c0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:58199d0047d736fc37d5fd8bd8fdcb38dddf0860370b5160a902eb483688190e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:10dcc6b86efc18c5ef9d538c61cdd400d2b1ccaa90b7d547c32f3b3f5ed1fe57
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:f9111d018caa3d7a3035082bbf1d07a27c79930749ce37e37dbb88c2bda050d3