Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 15.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

15-alpine3.23-dev, 15.19-alpine3.23-dev

Index digest:

sha256:e53d1e760346338e67a8cc0f06d2cda5c7735f7608a613b7881bbcc2a933ba23

Manifest digest:

sha256:3b9f1cb22f572bd9aabe669eb26725299c85098dd30bba6274b9e8cc378efba2

Size

133.23 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:15-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:15-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:972c76ffcb367876487c7df60be68ce3427ea339d18486c84ccb3dbe3ce7099e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:03a518456d6c6f1a48e2817cd22f3bc907595cab86508f1d2c96d172b25722f0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:72989168fd08613b0e4cac2ba1342afc58335f94b5623c24335fccfe6198b0cb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:332b97739c8640d7d4830f505da1cd6cf717c32a73fc28d5a080282d5750b69f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:84d825232b6cb576d89eaf719709ba5d0538d878cabea89c99ed2b39ecff8297
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:19fe6bef2f41ba13d0c1124bc275edafe57207b647276969ee9329433c2271cc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:02325c511d34c4438bf4aecbe4455a3b8061c3fdf4dcc1a2a84d23d2865666b2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:9cbccb89dd695ab68c36de65c56bac15ea8abd59b7b484219c313ab15f528f05
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:adf64a92d651d8c629b5d3536715d3dadd8b4e88a3f9022e050c26b917243dce
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:cd2999e02088751ff8e52165bd0fde0b124dbb94525ff5726efdfd4afcd8ab32
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:c51249cdec1ead16d197a7b2248ff1b7f3dee9501cdbaf3f7fe87547f7031df8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:1899acacf8d0e36bd99af07c30489e24199f1a693e5bd2c3ec02335c79164c92
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:11fbf00beab0811a2cd35ea8c53456a6c76c3346b2fb4574baaf8a4409554df4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:14239d42ae6d7d28e31ec520707de5fb4390df9c9191bc4c7556e4fd30f64c0f