Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

18-alpine3.23-fips, 18.6-alpine3.23-fips

Index digest:

sha256:f29ff7f9213be5644a0d1676f6854565cfa17bc0732579a8653bd684af25ec18

Manifest digest:

sha256:7d15044805b217d0dd0cc3b800be8017e64ed1b4fad01bbc4d2d30e9ae4a0827

Size

93.63 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:7847318f0ad7979aec62cb9de3a32d65c22f6124b19b9fcce66cdfd175cb6faa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:07d31d34bf045836e1a2675fe123eede5aa06dac1ad7c5e36deb530fd3a4f2b3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:f47610274228731f94bdb657fac56004f759a9a31f99f9c09e1f8be46c9b1b9d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:8d51b8b705c45316b6e95055bcb6aea262dd24ce812faa2318083cab0f21c66c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:fd34c71c6e42fe3585e48d137c96c16ebfd12028537de45c8bb1d95488690666
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:74cde9247c7bc520766e3e1eba17d7c42a69c7e73954d4b056ebb0127dffa868
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:13f736d5a6ad4ef0ba7d9d8ca76debec3971d45af153616ac1f40a330e35623f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:8df47bfb684ab38843bb99a5a303083f01e0f753c6ec778283f327a557777837
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:25f4c10aa373acea64fec1d8a68691a75647279b085f379888da4e9b96b07708
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:c2487b4b42d286d227f5d6ab539b2926174f23b51f6f0be1b35b1ade42231fbb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:9b5dbd95c03003425e4b05543ea90fc66c9cc5d23b73e5c6c70a4ca1786eac09
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:aea542dafc88edd43744cf05a0e5e96123921f0de854fefe0e8714221fa021d0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:f5ddc3f2d2a88ff82f116dfb09da09abe5a89e1b46519ec8bebf1dd1db7109b8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:8b2aa0b1091f6ea5f66138d69f2bc9f11f56447a9096d72e6520445b0165de32
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:df74df29976415cec66b1f151e6359878e7f57b08e1274232dd9e6d45e82ada8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:2628dc7c60d0f95e2e8b1669546b84a1d7b31ab6923cd7abc5792e034ebdcfa6