Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x

CIS
linux/amd64
debian 13
Tags:

18, 18-debian, 18-debian13, 18.6, 18.6-debian, 18.6-debian13

Index digest:

sha256:7b5b237b8f6757feeabfe568a68e8456587013942b3400a41686a14daebfd424

Manifest digest:

sha256:a19d581e2600fd4b27f32d39a3e8500e5b4b0badc839bde8cdc2ad635f856979

Size

122.21 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:9658df136de2239db32427b4f3700ba172fb47bfa6b248c0b6436448c185c9fc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:50120c3471003fe5369df862c36b4c72a02dc39801f728b414809080f3ace9de
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:afe9a701573f7617c1fdfcc9a115c45209a845e2aa88dc269e38718c13789c33
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:a26e37bfffb63c9457f6b615fe010233ab8340fba6e7322dcdaab8cb756fc75f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:022b0fcc682c5f702d1e1081c07966ba1a22cb3c14d3b5faf9d9b3e85c714475
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:ffeda94dcac02599be9bda41d093f0b31e2a0b4790801dbf83510bae44994939
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:cb60a76b490f71d65103068ee60150c2e8d578186cd6c6ec3d004ef5d75fe785
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:ba37811abaafd4ab4162047adee53dc1cf07160222cade31a50c824624f26bf2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:fbb2dd2b81a07737d3dfcfb2ca2fff7fa2dafd9af5d7ebf80464421291bcbeb8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:009b39ebb35e1fa769eb5edef75470709258b58d3def176845f884fa6c40538c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:10043791b156a70a25260745a113042ba97d30ca4d8b9fd4641844e4895b785b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:2a193272ce23bfe4a9646ad15f2809043cfe3fb8043e1f3758fdbc00740890e0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:8492f4214f33e72f849e28199f2e539c84b68ec6311707b347c816876044d86f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:17bc4979509f1b4ebb94b568b5ac73832dda2179a30f49d83121a3319c66e737
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:78c1a7dcf35ff5c8824d69d34570832aa4f8900e235a22442067f8b379d34475