Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 16.x

CIS
linux/amd64
debian 13
Tags:

16, 16-debian, 16-debian13, 16.15, 16.15-debian, 16.15-debian13

Index digest:

sha256:303be2db20f0060badcfcf884e26a43b93ce0640daa0f820a8cfbb797c0c5bb7

Manifest digest:

sha256:11454cb46dd1876eeb71468292dc103dead440b4e0935879e09f7b7a5d4fe177

Size

120.70 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:16

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:16 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:abac82a1f9d3f270830323fbdf603351009b164923b1c87cee3a8e0613fe74cd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:ca0aa9d9ed558cb7c74bda366c684f025fd23d44c3d2d406f7172f017dcfded0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:1e7a5f6eb7ed38ccb6cbcea19f2acde5b3427c91bbc4cabcda30686916107243
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:58b67f584a6227347e1c66f87731767daf11edad87a3be26b18a0a290fc73122
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:0eade89af8f326569dc2249dfa3abd959cf76674638480469ea555764eb967a5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:e6e90d848820705991a14f82f8541a22834efea4f735cccdb42378cbefddab4e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:7d396739c2520e7e0a839d0a850e4cca4fbe960253be8d701c101c89bdd983f1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:e66711ea3af9743188808f1a62975cbdb3b490210457e8f4db53d921808a207b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:e07217c11317e22564792d4f4cba6caa608d68a34ef7de6d281974930ce93d97
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:df22c7aee35214d76c73ba4ada94208698cde71216fc48a5d8b3768080e85378
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:b635cad27eed9664b0a9f6e5f9ce87f07de98d0490c3a0c8200a1717b6bebf6c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:46988e8461a2fb12d16f2c28df70b22f9e63531c08e3a82e6e59aa57d1a18ec9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:8b3796338e6aab84b976c4ec9c7e40243fec0be1624551e1e90f2a47e7092e52
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:84b54f99b674af406304fd4d91b283e9240315dc27bcf7c6733fcee71c64fbcb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:385f294178596b79d6b698b2ced9d20d657a5d44c3d81b36341550114456bcb9