Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

18-alpine-fips-dev, 18-alpine3.24-fips-dev, 18.6-alpine-fips-dev, 18.6-alpine3.24-fips-dev

Index digest:

sha256:51327ed598e5ac3f4a03d3e9270e20e209269648938d9db862e15aabcbdffdcc

Manifest digest:

sha256:374576ba63b8563b0e5f605edb3712699decb831c3e323904718962dc9b0a534

Size

151.47 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:378841a2e4651c4479686d6866903e0a0a1a181f03ef8f99e85ae188a4017863
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:2bd8d929c035512f7494c2d364a7adc4bebacf2184e8726b91675cfb657f9165
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:f76b4039de6b769c11b7e414718f0af3b709643aea583bc93b8c1b0db093e720
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:f00abb31c7599d0c796d0abf9491b28e4c4e0963ef5175c3ca03f752dcc9eeae
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:8c3dd731f5d1fd1767abc4386db274f12d7eb54202ca113e7276b4ed4a87fc35
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:dd37dd8126a4bbecc25c1f5aba2635bcc0f7aa1b0981446f2931a5b8ad0e17c6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:27786e67807353ce761c71bd918b709fc3908a52e49664786f722bfe7b58718c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:422ccd4f7dc9988503ac698ed39b4a22bae0ec8bde78d5dbb8aac3f9b36864fc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:f435f568939c0997e700be1c557e9e94edf7163b6dff346fa9f793da91221040
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:de9056eaf35c405e11e8201e3ad93494611582f312f69210659f9a7ed3ce9d54
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:ac9e89e2013dff4569e939c45c91a3ff924f2b622a00cad84975f445479744e0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:ed0ab9209106c2cdf2bcd9c1f1c30d95746f795a14c04528405ef0fd32c19829
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:4b8812da98f4eaa2c91461924d1d1bc8b3e757a18134270df9e75d61ea9d93b4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:497110edd222e246e7266f16641789c23007e709c1e4a3772bc339b5ec4bf24b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:5d9a51f32cca81280e36183aa2f1bb9d93e108c7f854664ade311d71c2e16213
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:1d015a8d6d6a8ee821fcf7a6eeb8e8721d5448f42b5b1765080582940ce2974d