Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

15-debian-fips-dev, 15-debian13-fips-dev, 15-fips-dev, 15.19-debian-fips-dev, 15.19-debian13-fips-dev, 15.19-fips-dev

Index digest:

sha256:2fb3453e9d60c99ea01581c03e81d9d02b27ce72a64fee444147ab53d15e479e

Manifest digest:

sha256:96ed618ddeb95980ecaacba3cb18674fc0e1727568f29d0a4076d4c7dc3337d8

Size

130.67 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:15-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:15-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:a92d8e5204e2917902817be0959a7e77c2382cfec668417ba64a1252d111fcd7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:8cc9a2c459ea9fdcc2ea221ac18ce6d9e4e8e4398242a35fa52c4fed12f391c5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:44c7c792ef24e413fe16ea70bb55a79a91adb34c731fd61e6653a17a578fde63
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:9f9d5ac9d8166022e23b337c423abc3bde78db6c2b528bd8f0c3f8174f309834
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:13b6e0f94c85d1bb0a772b3dff4834c72b2dc07335c9064ae64c8eb433e838e2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:6b1912fa0abd379a6957af61228c2242476aeb567bac502f6d9bbf565ba4585c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:a55db190204ee3d69c984a338b0b515eeec275ee3f22e468524c945bc2bd25d9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:54e4118a2eac13f8a4feba0877506ef67871f6e1ae3ecbaabdb14e2fa0eae02c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:771c832f4e660f606f6d2f82e272fec6b0a17aa2b84b70f77b3b4f128ff091c6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:f14af240ac12c50265aa0c76399ac9924798b0508e687da6de4b1f2890bad3aa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:af853281cbc7b6570bef7b8b77deeb6803258086f8fe0f06894265e356d31b9c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:daa8820583e1b676ea2886f03523470d1b15015bca3579396826b0cd92f39508
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:8b8e1071e2382114b7d1f3fb5b4b8a6ff17220915912e29af459950360c23777
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:33e87f5862b4008802eedf3cd0ec4e2366ca1901a675765b14e2b08294340b13
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:3ae06d6d23b8a9173862a08c16d4ce987f497f507cbbcfd46ea753b7e0907961
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:3692166b5c8734fb66e10e62f44f7516f81ddaa231d7c804412b7db227761ac1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:053299ce8898d4d5558b0db9c752e64ef259c08149ad200cce6fdca5db989f09