Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 16.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

16-alpine3.23-dev, 16.15-alpine3.23-dev

Index digest:

sha256:f06f33f15dc8251798e0469d1c993eb4a31d6db23510d9d165b0701a9e039f5c

Manifest digest:

sha256:e577fdba8e0b6d52d7a33459eefcc856be5509059fe952a307c413579e93f1b1

Size

133.89 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
2
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:16-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:16-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:e2c95ed706ca92ea0740342df914a9b846a17a3b3d660c4268a959db20658830
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:186c645e477ec0ef897073813ceb2402db01622b9bd230b347b2a3a0be45ac08
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:50fbd154eab83a7d293bbc67f20d73703f76c9a8643143275f4ab36fa2b43b6f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:855dec424b68331c83a6ea5962daf720c0d8d685f4c336f0c87eda63ca9c24cc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:66e1b150e51170f91926adf1522d093f4d05bfff99f91cbdb9c5adc8fa73e963
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:04e8934f2a55b9a9dff65393999596f88cfd39558204e3b7659255175fb39d9d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:836c368bac0e12131f86e4bec8fda437f3e1cfffd9b0e8a813ee8af5e5db65dd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:9e03f9945061ebb8b7ae427ec9b732b10935e6e80f44154de75d3ef43d43d293
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:bdddbf697321bbed4260b9f5d3cf4c3e052e95dbf9daf8056189af8dccf1b098
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:d4609a2e027ab1c041768c0e958345cf3fbeafcf7cb3225c0f07a5900c780cd4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:bfc8075436b6c0d3b7efd1d45af9bfdc69b5412abb372220101806530a253869
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:aff0374e605971dcbbba90dede39e2672c6f8ef1bed3b28838395b2499ceed75
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:d0e5ed78a8f808e9a9921f3efc7f8aa33f5502192578474d8c77fdc732ca887e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:5f39dbe700d6ac264ffde2f15360424b26a5d5118dae580d53a1d6c03787070d