Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 15.x (dev)

CIS
linux/amd64
debian 13
Tags:

15-debian-dev, 15-debian13-dev, 15-dev, 15.19-debian-dev, 15.19-debian13-dev, 15.19-dev

Index digest:

sha256:322abbda8a0b4a68043ccc86d4f32ce18bac97a8176191fe098be09275c72c51

Manifest digest:

sha256:76105c42566332a0f2095c790ad6d30e6b6e766a5e687f23f2a2847555004416

Size

129.95 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:15-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:15-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:c4e55743e717d3b8f35fc0e199b02f615369ee30f8675025b2280047aceabc55
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:b14358cab768ce23be55a8827c8b542768770bc48b4c6a8946e3ebb9aa8d5c24
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:e9e55d5389824f137a58bad185528932eea0e6ace34bb37e6554c7462f27c89a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:a2c97173e37490c254bc2a75355e574bbc0a0a81882f79b9e8169b1b87cd0d2e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:600315b2a0baf8f3a592e0df1cd2773aeef89ce9f4b036dd8487b6b1ce1ce339
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:06d1b66bcb33cfaa39257021709a0bbfe52152068c33fce645fb2769ed3d2911
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:50b275100593d9a0f2f0147c412d77c5765ef59c9468bfa537f3365b5b271c93
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:a571b3cb1451bf4864742d91a46a319195a1c9afd6654bd91e45f284c6d4bc2a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:35bb2deed92ffef886214a1fede675dcc22d3177f16d65aaa6cb36fba085d5b6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:9f741bf724fb214fdc15ba6f08adb5edd3903e951eae8b371083a56d831e3128
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:d188908b8656b486e4bb4eae0fe2ebcf5d6fb1a456e7fddbfe594b26c65ae426
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:a57e044a0526410eae14c013a124eb49f3f7ddf714d3a9f6b4757953dc0d7802
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:5b71b872d9046249585ef25fdd97b28cdd76dc86eacfa19b4b86b57b81ba8f36
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:0bd8c5d99a9b12f525778aff1020609ee6beb7935fceb0b3d739a0bcc2b16b87
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:c521a5a09f4d7a265fa6d4b5c0baab9d506e9f604e5c89d531d113969b68cbe0