Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x

CIS
linux/amd64
debian 13
Tags:

18, 18-debian, 18-debian13, 18.6, 18.6-debian, 18.6-debian13

Index digest:

sha256:63836d2fab4781db2f073b4e64c6f4cf1ce8042d2d894f62df54bf4ba2b63daf

Manifest digest:

sha256:3acadbc85a5cced75b82b7959d4e894d14b769afa33c5036330ddd1380325d7b

Size

122.20 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:b1d05bbdfe1d12c2c7686100337b9e2df294f0520f018ba4c3bc08173dfe311e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:e5d1636c5b977e58b5e67a37a4afc119edbda197bd0c765ea2051fc8dc9c9487
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:10637d435fb5fa0312831fabdee676c58b67cd0bb03065b5bf640573ac651c6c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:fe0aa8053482d7e05a76d90aa550292498ef18b666ba34cff22728c8e49b57ec
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:3237874076e2009f8e0f425f54045544061873b2894a788a66eab947b1f4c6f2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:52ac28ff1d2360127f886b8e48614a1da9dd63f33dcb7dc7152717d04db04735
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:b7824e4664a9a926f193131317d5cd99ed88f150cad6a6d8d190c3ac0b30ecc4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:8b6d357fef60710f8f86310c38dc2e0cc1be4c760502bd32d4e56aed10ac62d6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:2dea14985c711f18f09ac561c46ca33199fcd18bfdc28cbec25887c5c751626b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:5b93e1f8991e32e28efc144d2c4cee3b61205fc4ac52e15ca5891a0446a20a8d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:123a0d60864937cbbfd2440eff16c7ad7f1704bc69a7451cd4efdc9645a5e735
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:4ae7e076678bcdd5b59796674b662ce3642726adbf53241e02cce2ee0ed5f556
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:da6467a30fbc8dafb4bc34cbb95b57d3acb49c6a3be6c1ecec5a25c042c435c7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:8e374bcbf666ba49e35da7ba504f653775cbc5c3e506506e512ba1b58738287b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:68148a702fb1d4622b57b6fb523c724bd4d8e0e9eb8bb8e9c5f6e99b2ce26671