Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips, 18-debian13-fips, 18-fips, 18.6-debian-fips, 18.6-debian13-fips, 18.6-fips

Index digest:

sha256:8d23e67301fa21c53951f13482c2d18cf11d0bb859a7909a36d7f7eef1278f31

Manifest digest:

sha256:acc4df8534a099897c343756f15db6b2abd8d977e7091779cef058c7b9a1fbc4

Size

122.93 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:b60bae87559fdd4966b70678ca5e45c19d3bc0830389860e1c8e0401991a639b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:fb015cc0f47e5290ccea506e1c751964cee238db54b4ecbdc3cf7a948075826a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:968c2eb225569bd23d28670c3e79cf8ad4148075f7913c0c68582f3bfa8595d5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:658a2751eeac3b6fb60a76e25d957ed773ccc46613a35eb45296941a7c87033b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:43325d4efdc9bd6b84642abaa565f0c81eab75cbd2be9ddc14cc217333b1dcc3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:4ece9f89b7e4fcf7550b37a3ec12afa24c6026d4f54c53bbb4d6a85e30749981
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:bd3b936e74ee8683d72f2158d4d48b47387210f1c4066a70d0639ceed8e0118d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:f49555079f126d8557610871adc7628908234cdfa2aa9a902477461a83813070
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:ad67918b2dd5964b0e37a63c01061a3beea8f7a00210c6ad6be1b37460083ed8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:619ebae5f06b0bbc29965fc61d63f17b4f9ba685b327e7726749cbb0245f3e24
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:ce1540d52353b8e0426b566cf14f0ad4aaf5b84cf485e2ae860ef3cc1d3a356b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:7c92cb92813222a1530fa59657ce6dae7d6a20d00b16a8615394377211482d79
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:87e69be1f75f5364fc9c2c57071014a941c01382fd882726ffa899c7e270bdfd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:bf5b7a1d144f313bdb64fd0af5015f29ea3fca2652989230dd5f826788f8c9c4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:9e21d5e087ceaff74a5e90550f1aabc2c719afea541870a896e3981c31f7e0ef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:4c86a3d7713917fbda6f72998ddfa5227ed406a2cc26e54259c033eb091c3e40
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:b4639802c9ea1f14db14abdc8021ee3724080b59486e65c21fd8f34f4ea96ed8