Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.6-debian-fips-dev, 18.6-debian13-fips-dev, 18.6-fips-dev

Index digest:

sha256:43efcb0c1f73db790773195bb80987d66b5787c517627cdf1d3af4b64336a0b5

Manifest digest:

sha256:9fc13c1d13e51a798664533bd63edaf764b0b12de2dd82237326f25dd9320088

Size

132.84 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:62a9f08730e0f0698eb12098d4f85e6185b50f85a97c6d109a5f3aa35ce4703f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:055babd440acadbd1e02aae9cac43543dbfdc99e06fc8947f2db4ca7abf5a0fb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:c79c271ea3b34135cb8c6beb7541738ad0f723bdc6a1dc9ab02366fad631cba1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:079d32ef4b3fe55bdc784827332c105f03e6eb10dbcf365be7791a8c27b51e6c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:78b631028a71b7f666b594cd2ed4ec2b0f0984d91b67aca2cdde7f4b24a56829
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:f30b3452d2c9a38ecb8b113d99e925f014b124ea3fbd284fc2b4a2c095ef8d07
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:f39b2df609617350c355f20570493fbe44f16b3b3e74397a8a9c93b45b16600e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:972caf833be8943e713e96d32daddde80657643e42039bab3b9e96a172d55290
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:81e7ede2898a37f6e7ba8e8e19d7c715ff4a0b74ca255bbf3b88d5c781be1384
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:0f2cc822e7e70c958ff29f2aee53991968d15d080b1c2829491aca29616963b4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:1ec7fffa70f1b85c0d33de8687af5f710dd601a910ecc7f09f294ffc97b4e654
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:d471297834f5cef439643adcb66095ae67dadf2df088d4cd3fae31a6c262f1b5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:5ec7b9b251a9a9d084dfeea75371aad5c2191dae1ffc849c01432ae6db299525
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:cab740b80acf3403731f9032e1031a13375e5c7bd6e5e068949af9e0713f2d62
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:ca5928538bd20bd27ffc48b947c404ca16f3a48fc36603ccb384d0ba60d6e063
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:64af37f0af188f797fd8a6ccf3ad1eb52aa1abfc0b64a5b1dd05d5ed0a5263af
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:744aeafb894a9b0a0b880c40b7116c6d6f8fec01cf122cf4bfdf573dc16ff6c1