Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 15.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

15-debian-fips, 15-debian13-fips, 15-fips, 15.19-debian-fips, 15.19-debian13-fips, 15.19-fips

Index digest:

sha256:968f5bb47093ac20ce8427464dbbc67b9eebc13cd093deb766e6c549c1fca1f4

Manifest digest:

sha256:367582ba1acf8057aa2c73aa552f54ba02031a348131f8987e54524b61d34885

Size

120.85 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:15-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:15-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:2f005e6556b6a07da7ba7dfd42141c2e375f20fb83a9df7c0efb1ad584637101
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:107024c5752c26ca15a77bebe96bbe944f2a883dbaaea03ac5f8a78eaaf8f35f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:87c50787ecb066c3b0de649c555b177f72a497efd8413c157065df41a13564cd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:70268a7af086f91b5a978dea0993d077ba5b3c87ec78514fdf8b65f3c323206a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:aab85bc72dcdd38465b4b2b0c19e81e6d802cb9d0029db0a42959b11483defd8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:0de9f3945b43fdbb3a4004696f7c860fc922f769c7d2e3e338c24fc2abeed9e3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:14408223d310f9169cc3c604ccf536c9e9ae03a492cddf280c6a21da13f88dac
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:01b2ef363568a30219a125a3c6653a965469b4462db9567260893fa574d3d866
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:c3cf35344a9e301545a0616929400548901a580a8a96fc41be4662e2df5700cf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:cd5d9f7778553125fe77d38be0ddab7cce55a2fc1bd344a10355686df7628a43
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:140c879c6b3c40e38eed086e6c2e37207a2a435c1a546852e640fad446f9ca59
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:1f10157321b20f5e38b1f2aa56ec8cad4184f33c190dd6d2ee98abd3603a4421
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:e1a7106402ef0f4d05f1fdd2a0812e6a67557d5cb50cd5c444d08bdde4892109
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:98ceca783e6623532edfe75727afa233cb1831fc963f476a5ded8a8dc2e2b69a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:a7a0ae0de7a3185d8b6a4d0714b8718130d194a402d6729df3ce43a7fb12f77a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:9c4e9ce48d7c1b0e895f0e784a9cc9190153ed92b4753bce8a4cd57ee9f41465
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:f8339c6ac98787b3de1bec4059e615c4eeebe01cdc499481a83e45b8b62a680c