Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.6-debian-fips-dev, 18.6-debian13-fips-dev, 18.6-fips-dev

Index digest:

sha256:045931e83b4ab32f57be2c85f1c88b0628ed2a088a67101831a7958ee06fc4b0

Manifest digest:

sha256:9fcb7d05769aac77b7d10f7f2ea91326ae8157771df83aed0caf36d5e236ea74

Size

132.83 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:1143573aeea303d823935cb50c50391439beb851c98e4deeecdc71d587dc7b42
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:5e363c489d59f7de6267e79e784d0f2a9bcb4dfd1100610c00c36f2c21ccde43
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:3c5869cd586e73d20c7f05fe015cb8eebf64c955209c63522ebd86a56027665c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:0be38a73107329265fecf851a561b98581f73d1dd6dadb6c78def34c057a1543
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:5bc151b3ea32e3cddb16e773d1ea71c59f9675e709a52852aa12a53a928e907f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:a82712c8a656a0f53583b365f947ea4083357a5f2a9228446b3013c9135222a0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:44de0067eab3258967653450268151d867b34ead07c4a1caf07f74a7a039ab37
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:bf5faaf7abe78c6bfb61e9a88caff39ca30a2d318387dd9c0b0bbda7478ecceb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:defbe0120344706f21a2a33fe21c446c2e4a23366b2113965dc389da063830a2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:c5b155136bbc2560f14b777409569e8c334609f4df0a4becf1cffce995b3fd77
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:7c17f5d5502868902cc13500bb067464590ea9306a9c8dd03f7f5042e9b683bb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:6cc629fca1bc9b2c5b1f7cccd68bd0c581ef5e3fb62d79dc955c17ff2b7d8cbe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:1c0f244c1d2bcc6f56e233017576959049aaa180a048efe5b8eaf7e36e0ee3e0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:1416b3bcf4057d71167ce55923480f1ff3424c3a28622a47f37ddfeea0be7ef1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:eaa29b60123014ad752a08b2b52029cebf3df32503397f1505301d426c72bf36
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:907b144bce051a7ae01da15d8681eac4c9197e6693e5a82840e50dd009760c71
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:8fb4693436ca86fe92d97ed74ea6e8137139c06c4b693fcc73b295d95c15078b