Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x

CIS
linux/amd64
debian 13
Tags:

18, 18-debian, 18-debian13, 18.6, 18.6-debian, 18.6-debian13

Index digest:

sha256:893eccb38e6e8b9ee93f0f1d56ac2d817ae6ebb185248e705c4f9e7fc00b793f

Manifest digest:

sha256:56212423e541f60f6a509feee0e3c120a5e41ed021df967b672a23ceb87261f3

Size

122.21 MB

Last pushed

2 days ago

Vulnerabilities

0
2
0
1
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:3334d30dd252c23370f03ddcf58f18c94b42ea9c33491888e80f5a58cc34604a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:7d9340027c4ae0a943bd8d68cb7a0d246e3e899909514d7b7762fd874d46d7e7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:266f68e2b43f497d524ab710a555a7e42b50eaf7e0a6d200aaa4b41366d3b062
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:d2f3e825b8cff1890361599c4ac5aef7b43d5eeaae57dc80a7ed5bf42bf1f987
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:9502b875aec1c3814f022cd5dbec6efc5b6f3df7e5a6ac25baed5f0394419fd1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:99a051d9d6d6f503ac1b353a70fd51d01b25c40798388052b05892feb3829e9c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:6fca84b2ce9ff11f80fbfde5f9ff41b1822997aefb603a2298eb004bab1aba3b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:ef483110f1457d31664b380744d08bc546a50cbe85a2b4533233178baa101a5b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:b72712f60fae0986b60b7cc39444cf82642dd36cda06295dc1c328c5da231f95
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:a54dcfa85866acf81f5ec5504196b736c81ccd6f4f3e0130617a49b0a4320cea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:d7ae0afc5d2ffd0972a9c44fb76896f52adb860a041e1bf7022c9472ed174c57
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:b5505247ff3768158070cc79432041bad72f2b07715e5ee0e880ddcc8eae524d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:7228f8cf7068ccbf3bb8d10347d08f37be022f55367f0d5ad36f8319e616fbb7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:7eb49f978d3efc07c7ade8f4d031be5fb75eed5745e4668c20b57893d18092a7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:3292d0e934baaad689d128eefbf4ca97cd09fc6b1511519895c943e5c8478c61