Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (dev)

CIS
linux/amd64
debian 13
Tags:

18-debian-dev, 18-debian13-dev, 18-dev, 18.6-debian-dev, 18.6-debian13-dev, 18.6-dev

Index digest:

sha256:f7aed573479683ac083f0568caf10f0d54ca1912df5a49756a4a1b473ecf1845

Manifest digest:

sha256:fb0af9bb9d55442c85c10bd616b1b5ec4e96c70afcb832b74b3db6e17ab0040c

Size

131.98 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
1
1

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:910fc437f0748b6f64f5c818983d4488e7a30c3c8d53c8807725fcc834046862
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:7d3dff80ec0de0440576a74cf84b01e7de4f99b46164aee9a2b7eca316e6f497
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:65214be8cee12e6f7a3812c1cb11fbaa175c4f6f504713e8806f8ceac1e93abd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:c4cfa0b83007bf9d741a17a981f6fc24a518555cbb797d27095d65dcead7fded
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:7909c1b11757730eb6c63a97a4db8dc6ba0c7e6af75bdbc948ede17386f86118
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:969d976f25feb215c0625472300d9f9694cee6791aeb7abb8806e39248e6cc94
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:45a0f355605b932f6671f822afab2fae486383e4c39972dc03f45519460b5e89
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:b6c9d343db537b522ede7389648a7fd23e3f863873fe8815197d6de43a425bb7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:2bf53ff449b00732ad8e093b5e37c49e89e20a1a4a435f9633b969e4c20b138f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:0237f87a40f3170d63e1725bc644d01ea834ccae6e6232ae38700a1f3fd41c08
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:7703a89e518c35a2a98316c976a59732524f3a150e61d1f93f3c6df4de0bc55b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:c3483d36caa20629b92948a2d47125dfb61ec8a0c7a006d3625ca97e6e8c0955
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:37b3df23839100d994e5e83f0e877dbf8f7bd829b1089125e29d5718d2be1d0f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:74a4f2643c6963a47fb13a4033ce91ef0be8aee72086f705becc60b6b9efa694
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:e840e61d09ad900f25ffe3610ca5b017d798a435a6e6d469ddc1d6cead70d1cb