Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.6-debian-fips-dev, 18.6-debian13-fips-dev, 18.6-fips-dev

Index digest:

sha256:2a71b669b0eeb27905b9cf1f3d7cc7953f96c4888db1dc8caff51ed061589b10

Manifest digest:

sha256:b6623c4ca3cae809ee397d369f9aadea8a4f6fe741599728870d06652ee77497

Size

132.83 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:ac2865f6f4d1020e68ed2046c60a9c9a1bdee057ba9b388cb608b83b59e42ba1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:44b449e6a3851caff3f9738ba920bc008a0a699313187a71523b9573e6d19e5b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:3a5d77b72cd919db558d81f3e96d19e13822dafd5e6869378d14b09b0447e718
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:cf0ce432a93f7515fa0acd7e97e333fb9e996c1e1572091a5c774f3f0d2ca09d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:e2436d0cb21a0a7f250af2212131750d74212679a7283cde98007fa4efe98530
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:2e86d3020291f41183741e7158adcbb8930adf29a937ae6359458f48e4ffc629
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:b374f4a0ae57a82da9b41a4de8786da8fbdfebf1b716de8b6304be7bbe75c502
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:43c2dadb901ec8b085edd38ea32c935fce08b59ce8a32319a23ef5cf99928be2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:53c4f275276e7fd5c3c06b188e9676f75d6719245e8e7d09c75faf8c72c3a45a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:e2acc1d92091f12af9f236a970dcd7a4967ad59a0039066089ce9f11126a366d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:7009df3b36cdb1443880bd17b4cfae10f281ae680fc4427116b9816fc71c1985
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:1c9093ae23dcee0586618242f8f3f951fa41c8b72d60b8bda53c3c85bbca5f6c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:cc57b3b13c0767eab8b42d3c272ebd0eff0a70488e9ac56a545fd12ed84b6b69
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:ac2f1734a8cdab3a8ee78e3fb2a43b9f54e3a21e88cd1ea7cecba2268f5905a8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:2f63bdf98d14d61fd8dc4ecc58110e50e4ddcdc3dbf11546965ac64fa7002d18
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:005e1a8263c78b860ad08a456af084545b5cd0aef58617841a004048de642c31
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:575445958f8ad5849c32fddab873a1d5b3e0371ba5b902a7c9bdd1c5c178ad1c