Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

18-alpine3.23-fips-dev, 18.6-alpine3.23-fips-dev

Index digest:

sha256:981e7af608d5ed6e650e01bc32e62b1d6c4d1d88bbb7dd739ee2aad448c607bc

Manifest digest:

sha256:61a92dd10c97334825504afa819e5b84be6356b10d893d2a9906dd1c12b7b054

Size

94.66 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:5274fcb5843fc791e3eefc6cad05916bf549387e0fe2c8069b95058966388eda
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:559683a8dde3101c3862360686dd7c978b7d703ee54c2076d29c57d5bc1ba3e1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:515634dbd084ec14dd7162c255e6f3cf0d66a0a7e572920e4254ede7d1e50f9b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:90c4320c9776a27d45490eb1cf71507775b605216240c740b189e8cd7dca8ae8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:bca5351279e3364c60fa7060213d464d50b5977429f1c53dd124782a2fdac251
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:2e58f58027f6d695ab610c166f0aed45abea60f6fef88c44e6702856c9c3f92e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:6c0fa9e374455ca7fa962c9c139db53798e449222173062b4a50a748a72cd6f0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:d4f82aa5314acda23ddad7a2320778b91d9061301ca731a915802ffabc583247
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:28d9923c99bef34de9f5ef9910f5af1ef01e07bbf3ee3081efc42d7c385d38aa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:ff04124076561a4a54c83cd0e40a8495b4ded0291ef5a2945a4ab6d22285da02
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:41c9a8f95b948f4ab7bdd02a9db271d04d8631fdf581ec6ce8ed934d23e40f22
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:07d8b8c5cade2da69c75519a69de32b45d0616212366beadeda539cb983602c5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:68eb712e8d5579be397c2fa8d851545e42ebf58fd43741d0a840e391d778e538
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:4919cfff47a2c2a0156d5cd38e4b7d791db9994e0c96e164c6d62cd856b0ce16
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:4b91ca71f72434395213bfb47c53355842a305f3ba895226bc4d2a3b8f501f69
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:79627707e1a62c181b3e9a2f0f7af47951231d151b5d9af121e0d3fe4ec3573a