Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

15-debian-fips-dev, 15-debian13-fips-dev, 15-fips-dev, 15.19-debian-fips-dev, 15.19-debian13-fips-dev, 15.19-fips-dev

Index digest:

sha256:05e4587e5fcd332feb55a0f80d0a9b3fbbdd67af064c1c2fc9905f0b6e48b6c9

Manifest digest:

sha256:801626d56a5cabfaa5e5b1537fa14d9323a8fffb976dddf04dc020bc939109cb

Size

130.67 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:15-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:15-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:4b0eaf693069ec2f0726d5b8528b9df0d58ff92f132cd4f3bc734554ba2c52c0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:f297626ad67f2ffad5aa8a904ce5e88f55082facca91dc8460e02d2d4b330298
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:79197cc51fc958ee74f9f0b95b96ec3d85b0354fb21734cc01d283d21688c9db
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:347fa61511a04b8add761d6b06c4eddbd424761dda612387fd06b0cf9784f0e7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:12eae993bf77a104e6eea9e9b270b6b850ac648a5f962209795a8e8afb03849c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:d9e94a663b6fd523a65ecadd3dc36d5aa2ab798a0269ffe2ab8a3c566c826519
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:674fc10616557bc7832f0f590e18cfed158bdcae9fd3d2d1a309d9b97a5e2483
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:50aea820b14685220db3acf149770e54dacd476d1e289787700ac557c366903b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:70467b5676e020f1d6c90ed89191da35ec8dce45ae913e83f18fc66718430452
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:14ada231faa545054a634f932f9d5cbe39427ad89278ad53d1cb79ee71c7ec05
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:77c6d22db4e9061c3f2d48b434683c4d5d51ae91d032fee6293f09e9de2fab22
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:1e425d35860f4f6248757eb8749df527a2a7482964c6d5e3aa0541c6694e4fe7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:d8308ecc96c07d031309d511b0cd7877e8af93dff54aa34203f6b5c21f28b433
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:ac849a653a173ec4c6453919c85cceef2adb905291f37118740d0bfbdbc0b6ff
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:b60e2cf97b94c99125577e46103ea9663830330657ba55e24e3b89c5365564b2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:d4b5fb8393983f41880d25348220b27ff2ea365b8d6bad3da111b42e6679362a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:6c814e618170214c6632aad3c47ef2ae2b10374e0dcb244594a8209fdf226f35