Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

18-alpine-fips-dev, 18-alpine3.24-fips-dev, 18.6-alpine-fips-dev, 18.6-alpine3.24-fips-dev

Index digest:

sha256:7d7b02a3edfa24373c65f89338cc50295dea75f739b37fde6e6eb53c259eacf1

Manifest digest:

sha256:16d13f41857dbe6e5d0aa2df9704afc47d039a85bc5e0733743d8034417bcc18

Size

151.47 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:63cd0e68efcfa2b48c1221e4e002a9dcd4a6c2fbda2cae756af1d5ef7f090598
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:c1ccb9afdc530984bdd09b3f39ae38bfe9dae87dc0a4c7b6b778ecfba07f1e67
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:fb2e9b77084fb8dcddb97dfd41f23d6f03dd1734315ba21aea822c008388969c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:6a36238005fd5f3c8b4e6a16a4f5da8fb6d7934dab74f9e53bf3de03ac0e3bd5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:9c91a0dd7d6ea08d60c7f53638e8ae383c5aeb35a7b0dd8b3b1f68301b89e8a5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:04395a3688eda9cb68b85496c2e65a184b7d83b955992cb910999ed8a76d8988
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:a5d02a42d7f8a5b0d1f3878db2bbad0fbf662853c18db3e654d4fe33759b39a2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:23098efaccf4ed22b15e35c87577c4967bbf73efa36e0a71787da7f4a63c5974
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:3c1004ce5497b2c88c7d5764595718a0a469df94b0d2a4395e1b1d4b61fe1319
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:25a7b97e29830faf7e02ae92b3c0c64d2bbc9475931658476c7fc13f79109d02
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:c34338c2ec090433d971ded8189635911057b59affaad1f0c9e72fa1f4053f24
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:896df43d8f530cc0d9d8d0af0dd173420d425d909e02830cd1c37872accf6af3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:3bfb480da779c429dd8f585c27d98067a84a2dd86c13edd7fddf9d7ab65fc4bd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:e5d841be9ce7acc13a8aaf706f1087d457ced86bc5998680841c8db5bc85c7fe
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:74506d26f95394f65af36c539541835fed59887fc809dc6800598491cc219c21
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:94528d89d201131908fe552648211a0dd4b8e9710da01a4f5d19cdf445d1763e