Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

15-alpine3.23-fips-dev, 15.19-alpine3.23-fips-dev

Index digest:

sha256:4498790d46dfd58b68fdefbe4d3ffbac34c769988b960c8b2f1aa3ab4e7039e8

Manifest digest:

sha256:e8dc8fdcf75444b0dc9b043d4e65295b0d81428d253893f9f9b93a25fd02ef74

Size

134.42 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:15-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:15-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:59bd344a737bdfea583a16d03962221342b9504def7b7ced6270f480aa54ffba
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:8c4d7102a7f56a25f22e8fd7ffd8ad605c5774c066a2c3bcc42c51406a5dfb51
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:64c9fa7c70f47e1a39fe2893c1595306548d1f0c5a25d483d2d0e8338cd14907
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:440a2285ddb9acaae0e36e013bc47b1a084068561667d698c886dc5af6146b58
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:1637dd086fc84adef7a464a37fa2957c0cad61bc68f527b1ea2e9f54a83f513c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:07a2c18e2120220cefa05a2d73eae9d4a19374b16abbdd1c828d2e0e4b1494a5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:6b994ecd2c29e7bef8069b5a8f24f9729ca8418d68082e70d56dc0c0928fd9cc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:1fd933e9d6a0823eee0484b93f75f831dbaf2d8ece083e27fc2f2f598f673241
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:5a56cef68c1ae89f1f95a5793c9191b9b115aad9d418255dba17ae740324d486
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:fff503e6dd8909fefca882da8db24e376aad64a3162f235506029362486546f8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:05fc0ada20b018cef47920638dbfdb57669d2030841f12160454c9d27365bc18
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:215906b430df8d281fb97a0964c37eef5a56b2bbcfa6f4981df11547fedc27e0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:38e9fda7dbed652f922622c03d3d5c91e5ab94fcb20c9c1908917482af4460d8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:135f087c8de965e220196d8530a2ed3034af838fcd2afea174d015112c5cf77b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:93e7e60fdb44032a0d2f332128a011b2f0ef29598b4b157c71f2e26b67b73a99
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:c0170a087bcac8611043a61b01e4a6c91b1ab18049a8275a56616e4324ab6c00