Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

18-alpine3.23-fips, 18.6-alpine3.23-fips

Index digest:

sha256:261934e4be85da357e252ee7dd01445639be2574550ddfb8c9e786c6e15dfea2

Manifest digest:

sha256:4c5b1803a7704b22f405da8de071a54d6c5e0a9417de7a2334194fac83048a84

Size

93.63 MB

Last pushed

3 days ago

Vulnerabilities

0
1
0
0
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:63bbf6bc34257a6a5166d249fe931dd6d206dbd3b1b6eb5241382bd070f678ea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:e2f51f79ce6e7c2756df5829af74fd12b12591cd50462f68580d35fceaa75f5f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:83c1edd3497e3d5b8848c0541f7c1d8e0accd77273b5248f6c839d054f2a2d6d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:84c6848db3c806dbf13e1290c16e336010a4c2a530099849aad2174ddc5084bf
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:b55978aba3e3550fe1aa04ceead7571c3297eb7d00e9cc55684dd5fe0d2361ce
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:98273b615463002079acf5c819ccf7cbb28aef68a8977b74ab05a67fe788696f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:028004a31f4fb405e467807b9063f7b99f49093b3b3387435bbdb18f6ba385e6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:aa680b2151700e138912197514c38630e856041a37a9fe7b2eddb369318c2d6d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:6adfe82a576c4a6eef23eae3707ffd25ceb3ee61461e35efbdfb17b7f7ffff34
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:22a62bcb137fc7abe23c80c6ba612c6da204aad91a028fd86cf9fd693562d069
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:c3816e6b403143a18a62ddfd46cac39787465eba43011c7624e94705edf0ba12
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:a680c4b28fffc4bbc2423bb22f6d74fee9fe0046e137df7caf4c2bddf968abab
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:a847bc020aaf95d7d966ff4c0e648ad93e01b670d070009fcbc9fa4ec025c7e1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:9a8f90f5128a87035a8278464886d85909adeb105d2b6793d26a6ed70326eefc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:ae710b7aa5345059f4e99dc592359f7b799a1137cd54460c028af45689ac15df
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:4f15c2dffd0ab6fe010c8b0555741a0cef067c275c63dbfc0713874e9d0bcb1a