Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 16.x

CIS
linux/amd64
debian 13
Tags:

16, 16-debian, 16-debian13, 16.15, 16.15-debian, 16.15-debian13

Index digest:

sha256:7b3508d154aa7423a865a2022f1d10fabae14a79dce69b2c4f81d68e7b092217

Manifest digest:

sha256:bfe2f17eaec6b825fee5bd16a9323017f9fc468f0f8a3de493d15f2fbd38a144

Size

120.72 MB

Last pushed

7 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:16

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:16 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:17e302ac81843d53f3d92ba2993cd146f6e063957f12be445cd50decbdfe16fa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:293815661e35381e9bc4ba510eb23f31f5f2845340f2e904abdf4df1b13671ae
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:ea665dab8ec038d0f9692c7b58dac87e62c46cd47434e80160daabfc989e43ae
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:e800607f76523d240b6e921ae5bfd5a929b07e3b70758efa274669e901c853b0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:0a168d2ea92ea2ea64579638a0f479b37f12c7ab5676307b4751424c5f4a5a4d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:cbd33cbfcb0ba3622572284d8eb6065d55433f4a951f822b9f4a6fff9626f07e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:bf4d537f66f9d99406b7287f9d4cd418633e7616478249c4414f8bf2385e0a4e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:8f323ed80a5f2bc3cfea9330729e54bf24aa532fb1fc5d79d93295ebc35c7dc2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:2bad1bec8cc33623d9cc5563a1dfd54592ee3755675a030d002434dc8766c443
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:a6edd6ddf3bddd709c94d2602f7504c9f4b22afcaa9736b190a48f5d6f6c3eed
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:317759fdab264583f673d8b73abe5af50a6c008e37374b04abed9f44a1cfb714
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:67410899be36ea912683f82e94306a178b07fa5b3d48b5103837e1fadb62835f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:0dec02ad0fd4390840a9f13ddd169bfb2e920cfc3401e12902443097656d4f3d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:7e7fede3b40cb8834ff8417e6dc65e1a56d4e3679b9d0d34c3238988bf8fe52a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:d3856242a97a81ef85e07f007f9ee627bb8b7b58203a658ce193065cd832a9c3