Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.6-debian-fips-dev, 18.6-debian13-fips-dev, 18.6-fips-dev

Index digest:

sha256:2433ac6d7d1a3991aef8d2c274105080482d656199652d82e6d2890f87fcefde

Manifest digest:

sha256:fcdc72b33a3683009473df4969dfbb265113c5f1bfbf3b51edd84b53d6c048bd

Size

132.84 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:0d424eff2b365307030472a9a1bf9dc9c7e9835e09c6cc12115d83533ec08082
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:bc77cab3d39b5a51e66bcd43b3e315859ad08c689c37d775ff49f0975d937e7a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:891cd17e52b96b2cf955df80f59f608df2e0d204c927a83e61305079e563f820
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:66052000ea8c50e359d38be9c997b6a6d0ff24a53d2c0b3b2419508e01a7e138
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:f08de48ed4054b08417e6de3343c29e2865ee6a1d93c754d39d92692b37c87d7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:557d9ba579d46bdd0dff03318dfbef27ebe01f8898f6857581871d56d53e3406
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:8f48c0d1c3fdcc65d0aa949a6b0f000c554f046249b37e27f4219da1f3b87da4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:309049289b5f086151ee8091583f4c8a1015774442bdca6300cfbea6c1fc47a1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:c18539b62daa18b96691d4691c4dc9a1b5d0048078acf5d4508c86cb78ee05b2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:c97900daa1d9d1fd0a31078e0041433b13a8b0ea7dcc49c735d930a61b6d4ae1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:a295e2be353a2d380fefbaa58443f7aaef93fab7c62ad21212937542cae905e4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:5e72fbbea42bc29bcd09301d9969bc9c300a93e106bbd8b5265c0a5efd597dde
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:a2315d21097c72eb1ba9f8cda1560f4bb99675e2f0653d20fc3aacf5aef1bff6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:e5c4a3a90c70f079f36c0d49b5d701b2cc7bdd4573043bf1a61224269c51a4c6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:878a722a255cdfe2af02ce06f7cbd7a7bb0b6cc402b0ad9370ed5110b14a0919
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:a4a345638ff5a0f3da173eaa97677aca93637de96b2cfecb766fa4607a864973
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:af4e1bc57cc6ed5b4c2863fa26573e4882e9ee437dcdb8aa50afc849aba1fc0e