Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x

CIS
linux/amd64
alpine 3.23
Tags:

18-alpine3.23, 18.6-alpine3.23

Index digest:

sha256:ae2794bd81e4143cd97b492269689944157380182284e37a15c0bde20af9f145

Manifest digest:

sha256:3322f0617d7619e7f5a96b1c18209a5463bb88b1a11bb324fd6ce8e8dd1976a2

Size

92.44 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:438f6d26e3ee987b03f8cb59ba910f8d258a1dae317dddbb77771e79f1cc08f6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:97dba4cee322cb8d2c3f9b9ea475662d6de447db544f1cfac34072cc6dd2b45b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:118a3cceb624393baf979b16fd12add0a60edfb6b4fefb303dbed8c2f0bbcc96
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:20eec5f4c7392e49c147ae4d834bf7078cf1dbb0614e38bab6b9f1155274d263
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:ff3894278cb3599275d8ad09777f25c4f956def1e520c2603ca0e65963747fce
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:1bfd1ce64a61e17575cd02c9731d44b420121a7680c68ffe0cefbad7f37914fb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:c80f5e09a862494a22cd9d4bd0a4ce7f1a4970a8b5c698ea1976cfd45dfcff29
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:6418ad466a143439e07c5bc6be843dcc384ce471e28f8786f8ff142eecf023cd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:cfe0d4e798fc4de0724e964238999e6e9cf1c4978670b3abf3690160154640e7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:5ee359d769fe4b1420e6f4aab4f6630652ce7b2bb43d04dc9679781dce635976
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:b16bfadc1507fb30d7f2ad778ce4a86eebe38a1471a4d0127211b40296889635
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:6e365a09a8e1043cc030fc5374c6098289bdeac82883f73d0e5fd16f6d0f50c9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:c560cfb39732ac1f4472d5d7183aad9f119051d821cfdcf36aa0d38d1ee010a2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:38ddbecdf762df97413ffba936f3cf3a813a170bdc0374eac08cf51de83ca015