Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 15.x (dev)

CIS
linux/amd64
debian 13
Tags:

15-debian-dev, 15-debian13-dev, 15-dev, 15.19-debian-dev, 15.19-debian13-dev, 15.19-dev

Index digest:

sha256:abad452b9c4291f1c5accc7609bebac52cd3ca81bd07c985ac58f9d7202ebd4d

Manifest digest:

sha256:3e07f1db61df3efff5c342bca2a7ef720013e07f9aa149001a9c4c04ca82b647

Size

129.95 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:15-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:15-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:387b1b50f60cd70f8d202b2b86728bd45ff4f6c161ce8a677c94c845fdf9c4c3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:4e6828784e7fde262fa163b5b80c52dce40ae299f4a17c974bba2693b9ffe342
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:372be9eb73a4c98426768ce72385b9632a63db9a0361d55b7a2010e68d35e23a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:97372809d99824e64334d5962316414980ea195759e91d70628c7c73fb3cc6a9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:fba7d1a009a821fc15b7f7920a39d87e796f3717c1902c4fc18d042144887d50
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:a00354c4948b9ae60dcd38c44ca380a6d1b3665496b6622e67dc5669659e99c6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:6d400360b4132ba427594213e9cafb0fd02506cbdf431b8b4ceae2b027e3ce23
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:0d900e7ee62e4cfaf9a94a571d8a3118cf29f3104e3d7cb8c4fcb894d337ccdd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:e696ad726d639ba8afabcf5ca20aeae936f2830f62c542f4e01a6e62babe8bd8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:196021529bb65c4da1b3c7d2b7b7659cab722f6e9d0a6c3d13bb8d94497f671b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:cf8c152794bfee4fe1e56bc52f681823070a34d1a3899d33c86680359e610c43
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:97502214033168ecdf56db973c963f943132fe0a00898168419f4774b0c3ff71
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:4e463e75fac6401ead1ca1e7513f46b3f942637ae0114d318c6b2984e19a4dc5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:e03b06fc84815f25e2c5640a8d9ed0a58cb5bb770bfbb2ae433d3958db508965
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:8a6df9dc5181be622eccb03a50b5b3d72b70e23e01461f5b606e9d5b1721accd