Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x

CIS
linux/amd64
alpine 3.23
Tags:

18-alpine3.23, 18.6-alpine3.23

Index digest:

sha256:61a0e019f62458f07eb9634f3191af9022706c0640d37ef4cb3565313df48446

Manifest digest:

sha256:4d6ddff1c1b623002431d0ed4bd2515606d6b35e7caafb1217705e0efc3c9441

Size

92.47 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:253854fc80646d61c6f5ddbb7f8729ae0a3cd50103645e12361ce88682a0b7ae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:dab836cb6ae7865764281292cb9f3a5cc558562455d1fa5d10d9b59418b75353
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:8dcae849661e6a25d2dfb19d67e9cfb777061c28e088c40022284d1bf41450d5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:d00b74cf859c4ad3a768a729eba41020ec50451aa730b262d05fd48f108d5d6d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:b98cf5ad10a1453e6396b610647fbe9813b6785401dff09ee95897ad076ec12b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:1f975d1d351d5cc5baae9b0e6cdd06080c58babf8aedd43aa2a420b616968db1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:1368e69f8ca3551887a5a8f9ec8634158272f1dfc73c7fc9fe13f8a246cd42b7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:5b2e75e70f966627b89eed33e49af4f52585ad6ddbbacfa58ed1e14a35693722
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:1d9324727b5888d82e30405310436ae5f25c65243e1a6db1cedf5b7ec542cb7e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:5f743fa11cbdb320f64c6b1e0c74b8b4779e2af20cc9a88989c9dbbad29f2321
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:76c6d154a6493567c30d56eda122faa0036d4e8c0a97e8d7da02c6e9c09ccc98
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:ae37aa1c5a973ee7c372f906001a3a0d342a45b49464269e85f9bf40f575f03d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:dd0466ce31e2ce5ae736fb6d3591d2b66b27ee3b077ee15d5376bd857b84dd51
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:deae673e6a5db3f09a918faa79e447ee8b52c6006871343758d4c784f636473c