Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 15.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

15-alpine-dev, 15-alpine3.24-dev, 15.19-alpine-dev, 15.19-alpine3.24-dev

Index digest:

sha256:9ef53f4817a21d042a2927f3a610818a04544b88ee6187579cee4b63c41c18c0

Manifest digest:

sha256:d7b287edf7bbd28542070ee6f846235b758c5f31353ccb78a150d6b3410965a9

Size

133.63 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:15-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:15-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:7fe331430adc6c7c72261871dc6f24ac8045f1d52dbb19cea90a781edffca649
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:ee6c042f6670f1a56607b951f9089633758e6f5b79c31a5e6add175cb50c881b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:d645e32e210d4ae0c1f189b1e7a73b3ba92c26f7aea24f0a3cee34590d46e5cd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:fb3203f5228f2f18823d324f3721d96894d56155948c7ce30718873ada1fb4c8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:1e6e2962836fe383d13cf41cccc6404cdf76c3417d4962823a6c49209bf0c325
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:67a835af6cfdf19a229c3b978f3d485cefe9a7b2514955c9638bb4c717ba3285
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:ef7605c9f403e1d0d6922ce7f00c71cd5f971cff72de98a179235bbf30419d1f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:73237b59d01f46d57eb56afec4916e459b59cfa825f8ebc86e9ff82faad239c4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:af6b255a357a089144508150132a3a681ad6b48e9107c81e6d3052b0a875b4ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:00a895accac2dcbdfd85832fb89fc2ad4b3e2428364ba4aad694d95c525133f5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:db0cabfeaa4a0320a68b52d5909e26c17f49d2becc68d2417ce6e813817b22fb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:5b379a6adb861c00a0e4221550a91f1599c205850d5a573510fe8ff647cfa1af
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:3e402d9cb83650375762994e36d96dc4c482d9a3cc2c3aa9d63222b3849a2be0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:4577ad9ca0480a3d5c33b7e7bcd722dc7f5568fb9a73992179a2a2ccef5a7445