Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (dev)

CIS
linux/amd64
debian 13
Tags:

18-debian-dev, 18-debian13-dev, 18-dev, 18.6-debian-dev, 18.6-debian13-dev, 18.6-dev

Index digest:

sha256:890cb7b12cf5064455c7a9830c1a9e02517d038349c577418b417c0e7c7ca06b

Manifest digest:

sha256:8ba02fa77050768aa6ef2605dfa073202e1876a8ee31beba67afef261a2d64e1

Size

131.98 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:c00046bbbec1ab6eda07b872d8c97b97f24d9206059bc7e80dbd29c361a17f7a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:dd60215ff99e5932d482452a62d42717628deaa3b79619162aaba3c0fa10b11d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:780cc2050510792211e534ef55f48e74a68de298d7ff9d6232e2ce5df41b6e39
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:39b6a3f61370a44cbadc209bc2fbeefcafc5af65f18b0c9e5e0622f52377aa33
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:29b3c1c1912d8a5db46a74641578c9dd7ae9bbd0a38cef94b034037a529ccc78
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:f8dd323e367da38f0b593aeeb0b4b705b107e98271b5078dd31a375d02816bda
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:b7103a4375bf2a270509b846679cce3bd55873f1647f8e47de75f4020e089aeb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:19c55f3f4a330d6205e8e8e5154997e1a9a800fba3887db295f364e9dad54bf8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:4546f609484871aaac1f6d34497e80e2b1670e0b29bb69cffc33f02cabed0705
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:ec09ed71c472572ed3366f2364e30c92fddca2b6ac54bcdfb6402f95c8c7b633
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:6f5fc86793c46673360fa71c5283b931fd30e679d4f045cd62139cbdcdbcd159
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:de09439219597a42775f2a0d46b3313d04ec64a492e3d87b13f5a6805d0ea23c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:5e47196b5a33662130b2c282cec87710994fe5fdfafae0eea9fc107025b8b93f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:04c1f172bd35be8132e7b7f58590c8ba9b6d4a356e19445dd67dea8384f6c37c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:99bb210730e393799a0d6d66000e4bd914a1e3e6007568d15e0714addbe70b25