Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

18-alpine3.23-dev, 18.6-alpine3.23-dev

Index digest:

sha256:05078a3b2f9bfcca676f593830390ad9d2d07936ac0bf220c63e6985f21c6e92

Manifest digest:

sha256:b6749dcbbf708ea2d043505e8c145ee6c97aebee9e891d2ad80cf7c9c68d7101

Size

93.48 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:2e3034ffb3e94e9445a99dbfbc68d863097ebed6e8595d1e07f944f1216ee46a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:878070cac28c05b5a2310ae34f95c93bb63f35c34aebde59131f2d0af4c912cb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:632206f450b1be5f9d9289d998c2598a79257f86db9430b4371ab15c101317e1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:2b97eaec4baba26e7484053dcf70b35873f63e1292d57ec734c759df14a85fec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:48fa02e1b24ba5f94c61208b54330f496c8021b7e63ed8db37d764de5e0d8c17
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:742378701d6d364e29871a4eb35e0d5ccd0d905882c125d15c6478c6b3179e1d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:d3b2f8314754d1a978875b9d0450bef693b39ee8f6e9130b2fa895d322f5cacf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:0f5b03b02f629aecc29f41c06537b6adb09248aeb4764120de41839284815c06
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:3781d38949e594f9e474306a449852599444317eb70d91cb6a031eead857ed23
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:409a48aa83033b84fe32e588046a0e17b4c4730833920272e564664c24e25657
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:632b7b15af39546be0660f426d9c6c0169cccab6d9343437a0124c5fa8104f90
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:aef2a35172a46be206d11a4293709d426a351e8a2452da7176d530af5fe9649f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:f0e55d18400ede8876cb9d1ad6390cdb37a8de5a8365bd72c318769fef6dc5ef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:0f6ce0233805eeee7db15706fd053f90a9601f198e70897f7db63147a9ddb576