Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

15-debian-fips-dev, 15-debian13-fips-dev, 15-fips-dev, 15.19-debian-fips-dev, 15.19-debian13-fips-dev, 15.19-fips-dev

Index digest:

sha256:5c2ad42138b201bc9f5395b4e267387db6691188ce596b7a50004a18fa8ea555

Manifest digest:

sha256:b295a13b9a9e3210e78499889ccc790e3766270763e597f9bbfbd1094ef8b792

Size

130.67 MB

Last pushed

12 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:15-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:15-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:1f42aa36fd71c2c0dc8cf77d90c1c1e61eaf7a24005c65bd0eef3b499bbc6d1f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:172d670477928c2e61a2018915cfc9650096cd121b016fa5ee32b8dc39b8250a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:f1c9d18870047b7fee14cc1e12a131d615fef0ce659e0d2a8b163ab375fb8830
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:ff02fd64fff7f55d89dde45a865c9503f5c7dfc04a5514279ec7fdb06c8ba8d0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:94a0078d1f0dc623811b8761603770d86f0f4b3a433e5f84bd03ddf6558492a9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:c67f575e0613b20d0a04f92c10f32a4e1478807a58b279049389e4d4ac66e202
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:c804d7d0f6692da82a98cb57a1f564ee4eccb1c6cf27a7003e08ca5d5ed0d0e1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:21c59e2c6f867aa0d8c5d6b2ecad22916db34f5fa586d3338bc74aaabbf378d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:5990fe13450822b9b371afb656e599b8e5325f18aadd759794ca14cc7edc5f7d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:ba5d9aa013575fb7ff6e5b538bf3b18919da2826185de1d112eb8ff23e74a421
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:3f0bae70c9dd64548c21f6f8dae2be2949c33cec3a1a567e1903c510d96cb6ce
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:c94459253bf0f1dc76a3b88bd67acbb6e7bc8ed0d1a34e192b64ad5abf8c04a1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:eb91645703f0cc75db923b490e32239863218ba6d562bd50f491241849c314b1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:f4ff5ed0e497c4acd9a1a637dae54e3181d8343ab07fefd5c70969c22fc94fea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:18a50c9602622569ed280a28d5ba74f1351ff555ece7fd47c98ff3aed4ace07c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:ac5b8a2e4ff7b5ee304e8abf330ecb1816e595097f423311835c1c6e03900cd3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:2087e89cf8e5b8e7b8649f9677da35b628d489c697d3eae6f8f9186b7ed2711e