Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

18-alpine-fips-dev, 18-alpine3.24-fips-dev, 18.6-alpine-fips-dev, 18.6-alpine3.24-fips-dev

Index digest:

sha256:7d1065291f4c6bb97d65e4e3e87b7183151bb1227da475b56e5e59ba65f3b8da

Manifest digest:

sha256:493973596e52bd1a37130b32b98c2513ca24eb7240b1f25afe699e318490fa7b

Size

151.47 MB

Last pushed

19 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:a0b5cfab65edd43b396ef25d2c822d3aaa276b8f445d123c51b1021dc9c30f90
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:7cc007e0e880e2e3b714def69e91e9067e15391a821a1e9812f5ac64e8a3741c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:3707224c3f7019ac8e962f4b90c75edb1f97083fc2fceda01f016404a53d88db
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:79d957ac85494ff7cdf2a5b026e23d8852c1b2e75ee4d28dce92d636fe81dbe8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:65127a697a4787128762f25ffa308f393a9118b1b1713e4848be85f221fc66e2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:096762ff2619ca6d2b12638402cdc1a634de71d731e837649616fdf95ae7afcd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:117345ef230077a37b7fb5dc8ca85a7e833f059f7388c6b7134d7d4364986e67
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:96086070e43e3f29ca1ccfb99bfb2c7d823dd9e4d49fb99a8604363c83335adc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:bb54ea04345f795a7c917ec02683b519e2b87b32f8fcd638044f229daccfa752
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:94d5bad97f640568c498b03c537547c61d243540cc995b9550efd6d1f66f167d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:36c865a8837f389ec06df3d15386289c0265929b157c11981d35fb63b4d3809a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:a8d92a7c49cfd39ffba84f780c3bfd36374a862816e228f7ddf7556fcaf37b5f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:40d5ef6a292599cb02d752a71f7122ddef9316c8cf8b359d37accfb4a57ae287
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:a1734e92f67f972c67138ddf2a32825b0b1c3c377f22b8118a9b4d735a750444
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:ea2ba037bc1e9a1b3b63293c93a4e7ae4fe6d7f7d1b47925fc0bb09b5f639a41
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:a4a1782f57f5c4a16f4b74899443c040faa952fd1028b7685c360feef70f0648
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:cfc8c6444aa84e97774009748ae1a383e5df4d0c586aee4a607bc76761e9b64e