Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

15-debian-fips-dev, 15-debian13-fips-dev, 15-fips-dev, 15.19-debian-fips-dev, 15.19-debian13-fips-dev, 15.19-fips-dev

Index digest:

sha256:da1a12a9d205ee34d28596065d9ac92674f0e37d0e2d252a9c86b0cf9e6567df

Manifest digest:

sha256:e2f9623b9389d7da4839083e0f524d44b25ef9899aec5f3e42f1c75c672f33dd

Size

130.67 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:15-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:15-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:c20411fcbdb2bf3e8433fa1d90080698abafff730a70ceaf578337380aaa245b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:1b69fc87950944064a0d997237d2c8eb5e563b3fa09b0383e4dabdb95efdcc61
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:6427cdf3a3958c84dd8834f6a9ce2ee6ce1ba6399d6df3aaea6a659d16820ab9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:69e9f0cc8aa50109054a2d2d6b57d6f35156ddf67453550a448268f9c53ad2a4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:98eb0f2f73f71294a9bb4fcd3687ec225f806739ead25c703f1b20a1d1f601e9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:35ca535f140dd007246145619d2a70186b4cd863388501dfa959cee82f3aeabc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:c64539fefef291e4c7765e956bf76e3f73e6e4a9e8aedf43b74a3caf7c699387
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:46cc1c83a21008295e1dd755bfc0d3c660e95e20f8c10d40e8966e91651c63cb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:083b597ce0835f72ffb71eac77185b7dffc42c0cb9b76ad992bc5c1f8f2aedb1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:1e43e519053d3f675ee7904fe919acd3df1173a5f4adcf6fdff6841f1e7fbe64
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:ad047dd978d4fd7d58fe472c7fb9badbe2fabb255b0433161dac793a5a62333f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:1390957df52324309acf63eeefe9d1cf18e8271d7044ebf5ad3a2c4c61eb996e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:cf9b5111d8831aa3c07da77fea76b26df30cc97484bad0fce442d83604cbceed
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:0ae931111c6c47fd0d96058a11e95a73b39e86beec998116feaf95755ac21775
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:0bfc02137742e83b209ba6c3524b289f966c613d9274fbdb07148d3dfa0dc3fd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:09ad9008bb6f26dbca6ba9299521f1cefe6a092abd9de57e904b2c19be64eb27
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:7a03d73f73de7448f6270415e84a802baa9683e0ff6135b6815baf94c4b6b96e