Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

18-alpine-fips-dev, 18-alpine3.24-fips-dev, 18.6-alpine-fips-dev, 18.6-alpine3.24-fips-dev

Index digest:

sha256:5ab4bb7a5c9a478b0554912a00bd76577f61f91d7ea3a061bdef786063510a5c

Manifest digest:

sha256:dbf185030a8e2f48e69cf7e695367c189281306d0121d280b17c8aab9315df11

Size

151.47 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:7cfe41ff5cc45f637a4e811d10ccdd1ad2122ee2f0122e9fc104808ceb300f81
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:56cd252f1624334885247ee9169568bc9eb0a95425bcda050a5dfea1db3d7aa6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:ce9880ec3e34b08a5ebb399b2c5133ba31f92700d946a7c80716283adc937084
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:00d77d20e32f22e9040e9e876211e905fce45adcdc1042f1faf648f2f4274129
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:028266fc6c50c893cebca5c33c80a87848c7ee7f0d9783bac274cddb0083f4b4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:742a38c77d6b7c17276ca235c2fccc099cfdbdd31afeb05f4663b97a1d3ab508
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:066ae6ba442f12a6f701f460e9b615758ffe7fe55620a7758806c2d93ce963cf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:d48b7100baef01e7c76f971e6d4d5ea17b8f7e6804f9119403695436bf44ed98
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:e6e3ee802e9ee7f889830c1d030275276d8ffdefd96b0d4e49129157a2db9498
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:f3240314e5caf963f324820d582154b28c91b16bb372a8efc968b80ab2c4cd22
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:1ef531b10c59913cd6f1db3618b169951a4e600ed9331027f45adcbb76459a2f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:93ddc248d1fb38cc4bcf6469f3552ac7ab1639214237586343fcfbc2391cee49
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:d03c5be5afb21ba45b665018d79d364078ad50c2e06510b0e698b248762e1ee3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:7ab68974b2ad2400cdcfd3b2283fdb83dcc0f32b0df737a5c09ff6e928a2c251
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:47c11bf33cef38002d73a7f35442035f71e57d8e598c6d08a4b5bf93e0e5df2e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:2d8bdb5cd3ea9be3adad88b7b192036e9166872dfa69883bd7bf417b0fe6ed18