Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 16.x

CIS
linux/amd64
debian 13
Tags:

16, 16-debian, 16-debian13, 16.15, 16.15-debian, 16.15-debian13

Index digest:

sha256:ff885ba89312667e36351f0bfc741cd65a519aec36488bbbb4b23169027b4eff

Manifest digest:

sha256:b8079a6cad172e4c846ff98e7eae2d91d57f3a10f18e86e519a92587a84ce5f9

Size

120.72 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:16

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:16 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:e46fb811accd23d206a292f605b84b4d413d3e07b778444ceda14da1abc6e289
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:fefa1ba1d3bc3b139a0172bd3db27be2171d013c2de875fd46ed0289679e9c97
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:97053720a3cff5b5ff40a3581659db3d24461cef0790b50df525bea6e3d7bad2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:cae2ecba876f75af33c40538e93d7a3f01f32f5069614b3c535189852eef82d1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:1c95283883e379135d34bf6e8b9b579508b8df86e1c0567e41067b8e187dfe48
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:3dd0538b6a1832990b31de67ef3e6e59b4dfabcea7d4ded11a44fe6e5752e293
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:813fed05dc189b8b4bac22553a24e1d5574f17048e1427444c92101e137ffa15
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:7cce15413ab7c68c28d936192d1af545f89d034da1befc52c3bab0e99d37c4a2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:93d1336a0a0516a956f07a691c7481582355bee6c8688c178a8feae9ce8742f8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:b3e7499a4bab36e5ff03cc9934930a5e8e4756f4198241b6d86d097a2185adb4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:9895a9f544d987600c8a6546b9c3fba2f4ed9c8416b32b8e1622ed41ee324438
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:7272d5f57abd9d2fc2c87abc7913155e531efef4dc12ca054a88636e3ddaf531
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:d89e44910c20634cd1b84a4db6f7d95802ee3bb744e37db33166542ad6b49050
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:6fd1ee46fedb29dd01cf26e6068b5afc87131081de2bf5c56a45a150cad3a4fc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:ec23ae1167d770e58e1aed04a6213cbf10853fe436ad9f0365afefcdde993f1a