Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x

CIS
linux/amd64
alpine 3.23
Tags:

18-alpine3.23, 18.6-alpine3.23

Index digest:

sha256:249053d2d4319239d871e7505ef0818383bf2ca6ea3b98174311ca095a652e82

Manifest digest:

sha256:db1cf4ad401d50090db8976995e0742aad4e4620be266f4a10ab2c780f28bfbe

Size

92.47 MB

Last pushed

52 minutes ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:d11fc81fda311a068f2b5b0bba78a253f19069bbf041dc7a25d047e9bdb9b3a6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:a82637522052de29e009096e4610e4c756d3cb1f5c7720402c382f183efd4171
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:2de93df524921e4c0f2773f4141085b90b1ab33eeeda419cac1a57e6d3611465
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:f9c95127dadad60a8ffee85e49a01f612525128444c5da502c1c68dfc33a6671
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:33fa5a28c09feba0129a8b190c5a678a21341b14a81ff061ef50be79bb383a28
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:d8ae0e508acf80b8e37ffa65c226c5076cd4a89edf8ffbb0ca1262beccf7a470
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:afb24b69dc408f7c3bef4c54bef859f31568d59772b001b75c6b3cfb7cc44dd6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:5775fbc03661282379954321ad4a3243938f0c529a80483b280c927888b6242d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:9d1ffd6f7d7d5229e60fd19ab751012b29bef8ae425caef0cd24754ee82876bf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:d31a6953a3925cf52524c412106819b95a9d1b7341f2f132f98e0c6f32c624c8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:db3d6a4a1c136666ee3103da3d6fa9d8dfc8478f2de41251a192d91d7d3c6d45
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:7a8f190029d1fa92a89189688da0e63c4dc26b758ec125403a7bb2b20db66bbd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:84624681deba021f22b2073c387a60f6d8d6afcbc95dbb2d077268be9a155af2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:3100a2b1421278fdfe5d05ae0672665fd6461725b108421131bc304230405de1