Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

18-alpine3.23-fips-dev, 18.6-alpine3.23-fips-dev

Index digest:

sha256:242af1e321b0472e2518a1ee694447f5504cbc098e3ad6590839cd23b532dd74

Manifest digest:

sha256:256e41005e5e55b20b2ee7f25f63e83a8fb7eeadcae9e1a1669dbf02403920c3

Size

94.66 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:9667b0fc5f0a286935886e4f444ceebe39070a9d84ef0c43f02ed6ff2abf968a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:86e027a816b73b49c1ed935fc4f76a73513f3f4e3c6fed6c847bea0d1753e563
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:4f5724655b3ed908fb6b652c3444e11f9e1a51a324f70f0eed73c715fea821a2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:f5459537a872f994370f2e56d0f35912eb63056e80feb4c6328ab4165927406f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:6de6e43e97af6703f11f7d5850c2986b982e5e3a9add736b3674003b8965a1e8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:46f7ac40807a498c5c0a2f6a6d0859d64011c908d42623fbb0f97727bf73f9cb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:2abb15f7225684cd8d55d4685ec1ff504d17770b183eb754da1336666b1f4728
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:70e22cfd6ddead57d53d5aebe95d8680b9a1b73f2a2fa125eab8368605b55a9f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:32cbebf33e21e3b72c9fed7d8249b17fd2337c27cdd1cb42dcbcba5e0301c32e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:7a28d4e279201c45dfe7714b32b7ddc871ae87467776048800ec57e228c626ec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:0e22a9e458c990448e1df3005b5280048c0fd78ec4f34b06fd949c318e6e2c4f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:0f4cf03aa8181e0d30a9ec1f8956572881908a74f4f9e6f0e7b58d89fb71f836
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:eb1d4f5fd84958e6d483274b95c542f87d3e38e99de85f17b552c1954a165e46
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:802f3cfb875e18643970a890be62a224f3dc78682751c5dd5c86b83401f00504
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:775b51abb7e760c3c2101711ba6c3a26df620725ee70004fbfd41e347c4a1511
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:ff6739b35068804df8c79451b6066f6c02b01e0f27dbf845b27e268ea7a94485