Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 17.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

17-alpine3.23-fips-dev, 17.11-alpine3.23-fips-dev

Index digest:

sha256:1cf315aead1d18e42083c214c24eb2bf95ba8293f78f94a6dfd0bc2713752a81

Manifest digest:

sha256:bbe563c7c2210f9722949eaba14093e961089628e2ea1a77bdb8042c8675cb01

Size

92.31 MB

Last pushed

6 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:17-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:17-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:a8c393af591a809bfbd238972e88cff25feca5530795a4c1e741d5ec17a2024f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:80de89791a42437ea8efa30a9abcb6530911ed24ad1bea5c72db47e157d69ce0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:34008b1474be0fce2bd3e4c89888845c523f19d42757d263f9a99c2874ea89b0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:697aec62cd8283b6b9ab0958347e63872fb2f65212a4b6670ed1ca940ff36111
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:ba971a2190707b6b1ae3a1c87b40affbff7184f41cab1517933f519ca891b59e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:5d8e64ccc7b2ea28037e17f7bc21e25cbb1886f2318f7d28b5968cbec962ad58
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:5060b70ce3754cce1a794298a30a5af037263cb0d4462c8743f666f2ffd15b00
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:bcb0dca43668f492c0ac4b0bdf91ce24bd9f2dd86ace382071899df5fe5a92b5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:84336244f18b38e67d0d870f602e7b2a3879646ab33bd9f44c133cc48944eb13
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:ee404f2a56812c10f02a27f32ab477b993a50bb3bee3104fe65d330d38f148b1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:a6f9196e01cd13fdc89ed784010d811bd4504e3c656e076e321b8cfb0a8df13e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:4de94e19594e3b05790e914b518cf7a7da6760e63ee16ab176938f99d76aca7b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:d616610e2c96462d6872061cbdba2a9d0847aed4a5c1c9b0c898ffba8ba2f781
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:ceb67764965d4e2c9506c8361c53c32a16127ccb852de2cbb7eccc180bc245fd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:5068b73a3246291f68a607b9dd3cf2499eb871ab9b4b4f19acc56df9262940ff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:48b69805c4fc6dd378e58d733bc45b9749e44b3ad8f3937bbb7d4c191b32c343
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:82bf4fb55d81c094ff90f10a83716c931bda8720a497ea2a66b84a57d79db85f