Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 17.x

CIS
linux/amd64
alpine 3.23
Tags:

17-alpine3.23, 17.11-alpine3.23

Index digest:

sha256:3379965f6c91805f4dbcfc8ff9acc5998312344660a432a22b3ddea041614498

Manifest digest:

sha256:bb5f7c7ba5cdd87f34de5e682f4cb5214473e073d754c1e3cd210e14bccf3d24

Size

90.15 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:17-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:17-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:7fd4dede8ed58fccf9dcddf8a7f0fb35fd30bc11b5f96034a74c0b69d6c3edd1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:ffdccacba7fd12fd6d4b45a326873c7d6921beb1fc763a8834c103a586b45b5d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:18b12a28f4b9038a624bc78be92292e2895c9b10719546faab395434e67f4b13
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:f29744d0008e4e2590cff1fb93ff76e91228adaf3c60df53141fe30dbf18db30
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:1eaed5ee36bedd521bb23156009ab15ef77d4e4381339cf88e53522af06fd431
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:3c4e1da959eef34e2656b2d4676994cbd63122676e43ab0d02ecad914bb40d2c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:15039680ce1c4161e44c7668f21f60012a110bd58f1a6e7ae430e9a24286c497
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:f4148e85d52cfb3540629e4c424788b4536ae6fc3b3ab0f880403ea1b6a4048f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:4ee6d5e2a19cb1cd9aadb194a4737d3e2e2e81055acd91017825f269e6feb06b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:9ea06368b6beb1316ecaebeace4aed46ef21e75ebb1d612ca5c71df976ae61e4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:2a314357db5ff8bd011023adb1901f663d66f0dec1ac033009b2ecebd5599430
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:a5d12f1448b67828505f9e2b8eec0490a738ff85532938e8503d00587d00c59a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:f774a0fe2aa5f6f0483fd677fb89dab8397a8a9c0dae80db1ded2e9889ca697d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:4820d84675099b6b2614f9f93be74608dcc0270cbaf90ff0e20e68e2271fd70c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:55a2c8c4f8ba9dc54c54a25c1e27036464ed2c437cef01cbb38752d25f19869e