Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

18-alpine-dev, 18-alpine3.24-dev, 18.6-alpine-dev, 18.6-alpine3.24-dev

Index digest:

sha256:342c22ced14d58bba133e8d5ff684c6b9fc1e1d2a12575bba651677e21f91be2

Manifest digest:

sha256:2bfe18b4813012aae2886ded5691a4ba572494d5d861a6bb8c6f2dec72d21a8f

Size

150.29 MB

Last pushed

12 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:b7dfdd95c025894681c197474969b0023c70e27e51bb22e5cf77a8bb6c9d2beb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:0194e4313fbadea110ae381ebc0115ba5aa571652a8eae0cb85108d3e41df4eb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:8fde585cee72bd041e920474ee08c51f27631133bca21d9779ad6b45ea41e429
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:49508ecddc276ec2e3fef2cf1b171876158eeac2f4600c51253b4e6a55ea55a4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:59f1a1e14c26781847fd95da63c46b734144a6a94f88f3248bf5c62f19874686
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:7bd1342fb724c747de3fb7f6404039d729904dd2762e4b8163c6a703f84a9887
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:857d07fb6a4d171de5ce4643daf6a27b577f82b9dbc247cd1315c9fcfeafb601
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:b7968ad5ef06805c8bc082be74525a760be70ab7f39f1726104b983e164c8f25
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:bb8b279a68b1054a578111aae780b2c406e9acfad8c43c94ffdde3fd208ff61f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:62cde74afa9e7eb11e180ebef90d0609303ba27d42664a76d246dd4fb4f98282
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:2df585fecbb6857d04fe2e34b27cd1a0f361309cbb5537a73783a67924a03925
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:533c4cba49234e01113f9046ac089a1cde402972da9643a7537dd5a2fb0fbd27
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:b61c0975b16dbe4c80d96fb28676df039afd7ac22b2d4fcad58eccd1102e1698
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:3ad9b5400ebbc32b4e90991cef1848aef8de1fccc84455dc5bf495f289b6b3e3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:200c795a7e05b39a8014ce64cd377a9638afb501be7333469c55179834852004