Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

18-alpine-fips, 18-alpine3.24-fips, 18.6-alpine-fips, 18.6-alpine3.24-fips

Index digest:

sha256:c91b3caa6bb74a6c65d4772219b20c06b21cb5be26f9f81f06c0efc2b046dcd9

Manifest digest:

sha256:4eba5a85d55dadcab4b27b773ccb5924d4b6d3ec2d9757c98478b6d82117224f

Size

150.34 MB

Last pushed

6 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:d504ba120d7a7ab8b188d979ef650e494ff48805e2468bee88010cc0a3c71c47
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:95a2757f637f1398089b5d1680c3ca1713c2a78e7f13f1851e3c9251b9e73103
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:0658544e1db4720af9d9e7e5db84a63ef41715bb1107db0c75b1230b22183954
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:a0ea59887c87e1d6848276882b3e728aa181fd7dc3bd73fab22cd8920a70ff70
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:436d545970f4dca05837c406af0888b566f7a992a9587eb0729237252f53bbad
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:bf966211c905ec5e85dab7a5a50d5a3a0fa8fd737c13cedbceba1c070ac22ee2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:7b8033a833909b1713e40a0f9aa536cd673eccb460ea9c82ecebbc3765c2ba1f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:81bedc03b78163c4527f10eeb554b522c8c103283003c5b2f0d9a41921d102a7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:98123a668a21ed64aed59f1e54a1c7a50439f5e5e02a3e26879eae4044a2ab0e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:0019e886e4343865bf328879a1deab0cd7ae7561b321946858785b326ad8b497
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:796f9bd37b0cefcf154298b692c878b14b87643beba93bdb4e0fc98cdef33b8e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:f53343abd06c6325738adf313716767108da161ff7e317f514128595875d0d01
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:ce249a5be30019438c144d71e550263f21f3e942ae941d22c71cd631ce45760b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:da55329c1a7aa62601679d4eabc71dafc37fc6d73a80f5aab5cbef52c9ecec1a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:46b52641958f95a4489e2355587ae5542472e171f8d0ae79445e9c51025f519d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:7ba546246a93ed01dfc5cdeaf9d750384da783dea73381462a70050178df19ad