Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 16.x

CIS
linux/amd64
debian 13
Tags:

16, 16-debian, 16-debian13, 16.15, 16.15-debian, 16.15-debian13

Index digest:

sha256:876440e325da0af8bc2ca52fd9139f4422edb472f8c6252b923798703310b3e9

Manifest digest:

sha256:a2105967970e127e81e147a90e9fdf2901fc565c62f102f77ac9f30df196f176

Size

120.72 MB

Last pushed

9 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:16

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:16 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:677f2d6898d9f72c4f86de58b89132f2b506b712a4be928713ec092d52267f88
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:9d91610c6dfdd0bb69420d7df48322b2c769d909138ef190eae8efc7a88a8533
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:3269f55dac1070eaba590cbe193ebfd7ed265ee55d1e0137e54fbbc1873a5531
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:d5e29780808111f0d9b80649f2cb707279b4563c120e788768f0a8651cd1e8d2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:bee30aa5f1fedbf4e7798701b0a006c1300951447edb45eb236e88fcb2ecc92b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:ffe09f9999122361971eb7ad6209638b7ecceb6c95672cfaa143126c7568b3ef
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:2cb0f3d6891061676f4f9375f2c3e39e9b3937b969e51fe80d27ecb98640fabd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:82845a387897a4070dc074f19b2a85ea1601090da601c42b6962f16a50c38759
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:34decd27f942190e96709b824f0787da4167f45aae3b3cbcc067d49ed7795e67
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:10e508f6cafdedfb9033f97794eff07ac081c998ad61a2433c7a122fb6ac190a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:31c6b18cbc1d7b81e17881c3ae2291778fda9c9484ae9a05642c4e6a1e6ea428
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:2a59577b2e1b1ecd79fd7bece4946a39c2736ae484360026a27d234aace05062
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:653342213231a2a34b0fc3a8b499126bc44691b59ae66e9791e6a6ca9317cb31
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:373070ef30d6ac45bb25977c89f1e5c97104842016088b01f4ff91299829e391
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:a50773bfbeb0ce1415364f566d29d63bdded840606821ceafaacc3b0032ab7b1