Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.6-debian-fips-dev, 18.6-debian13-fips-dev, 18.6-fips-dev

Index digest:

sha256:da6ba82b9ecff61b048b5f159dc8e0a8935f14e1f414ae3138d7f82c0b8b3905

Manifest digest:

sha256:f183099246323ba6c8c9fd648eb4bb15371abe1b8c9f7dd339c77b99b0e96c66

Size

132.84 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:2db6b492eb4033fafc52bd53f5e9acd5ef5f300d711d1276b43b445df3dc461d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:27e418d2ec40ec0602879b888987d3b28cc1bdff85691589b64f6b982bce1756
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:cccfbccc8f3a1fcf946be70144e2f90a8a8049764d0de14c933f8b80a018adf1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:c57bc0d7368484c2b5d8335b0d8366a5c1ce5290d5e977c6ba35a1cbcdc31fac
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:c989a1c9bb5205d4cb2afe55e1e7e79edffbe244beff75b2a8ba7f33fdf0f7e6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:0918160cb0c203065713b7082e31e2e42760833c4114947f0d8de5445018b46e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:047388b5d61d73d2ecfa93db94465b4ab4cf0de4fa2ccb46bdd335c16de9190e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:83cff1668c2ffc3d92c49f3ab12d283476de38b666dc6306e8170f790480cbe1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:18a71b4730e9bfb57543ac9afb59297be2b2c9a1931c5bff19b8d2582e3d7f85
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:09ce8b8eeda0d3a2f437cdb6bfb41dca4d2748e8318ba65ac3e232fc5b52b788
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:ed775d79060572a518ab9b0608f78acb709ebb5854ed2a90b7c32b65f2702cf0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:90edcfb2c33b5e81e893aea43da7b5fc1efa8f5e0ef59a11bfb367a8a6be12c0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:25c9d1ce662c2138224a2a24164cd112118ece3d4fef22f229675b5028f1e939
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:f3bfcb3c58a9e729087296545821e871da830b6cd846e0820fa652e9318e25f0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:51b9ac3d400693c8c189f445c5257d28ad8f0b23a71d139e1f91a9b6d047e024
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:5c55259fa580b86e696420b40fc4ac2f3648f97c7ac653aec45018d038dfbb88
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:b652cb7a0c4c3d53b4fd91d1c561c78d19913c11afa39c2e3ce05b0badc9281b