Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

15-debian-fips-dev, 15-debian13-fips-dev, 15-fips-dev, 15.19-debian-fips-dev, 15.19-debian13-fips-dev, 15.19-fips-dev

Index digest:

sha256:5b00b367e6c4c444e927211356f90d85416db2cb9613638b6162573be8dbbae5

Manifest digest:

sha256:4227024591aab04d6023eeda13b4df10b69e8ba64669be6c659cfdc07cd5fc8d

Size

130.66 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:15-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:15-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:9791eec771950a6ae36b676cf9c4d129aa479c7bd894d99960d669cf5768196f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:e65f01d6d6163ab120a5db7b82ce2194f609745176bf00279b52f46ad35af411
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:d2c1593ba5e29406eb5de548c75b948961f732312e8d064816bf20ce832bb8d0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:d8f048af0dd2dc9d4d454d5ba7ed1558e90ac5a9b13b0abcbcf9ef717df78fbb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:e4667e1b8913e9638f6a46327d357b627ba3ccc4da3d7df7c566fda7e3f7aea6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:d6c386a4a82dd5c00a07f8091da82e1fe977b5bb3c6ec0166539d97bf94b23b5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:45f4a85c616a6e66151a95ee7b11d6471db886cf15d2bd05a7fcc6745c4dd5fe
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:e917f549802d1973b574c0b9d5b7a8c3728f139c7158e70c2b061eff94280116
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:27da55f230455ec2bcfb956197189b3dc9e583b8a8c875157c65ba8b71e895fa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:bbfd0a5379cce1fd337003c4318b15ca0434ec3a4ac55882d79c2ff36f92d2bb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:e1d69d8693885065a0009cee82d8c48b42206c5207225150c8f4373f76d95c68
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:b022f16841b300cf95b5a965b8e3f27dd5f10c340bc613d64204e0ba14c52fd8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:4e3bce8b357b0bed507dac208ddf89e470ae7dbe9354edb6726116cc9096e947
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:d8614100a13a49b19f90f7090c7650d6fa401a4e8ad9c8d0dd403ce4a4af156b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:f9820a7080558099268fb85f4b86d350ac5e7555c3355dc8578f71a46f6a8789
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:23191f2498f7c78216de0b680bc566015403d8e2add82a57fd670599ddf1b19e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:348a18f770f222518ac7e245a02b45062078c515ca1a4ec112bc0735d7801044