Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 16.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

16-debian-fips, 16-debian13-fips, 16-fips, 16.15-debian-fips, 16.15-debian13-fips, 16.15-fips

Index digest:

sha256:147089a05bdc12ee624599d809a60332f0a6de6a22c4d9fa5fa71305d90b6257

Manifest digest:

sha256:765d9f2dbb8e5b0e8b34bd7a16323abb945b837bd572218a3593d01e0f683a60

Size

130.61 MB

Last pushed

23 hours ago

Vulnerabilities

1
1
1
2
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:16-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:16-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:274162bf35a81be4f4c7c3564fd2d218d38faa27a59a2b65a8feec0c7234c690
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:1156731f8204011bd154c37d190cbe4835e476cc6fbc423976f4168329c18e6d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:937717e99aa6afb6b30e11db5d57efc989cc3a0285fabca46631144b952a8813
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:214316b4ab722a59cb40b5f3b268d38bb2139e061c0b9182e3db29e6c4fdd179
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:c3832df28f64146b54c30cfa79d77630ccf50067ba052a179ee50c93879a7766
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:dcf0e863e22d1cbb5e865db3ffff731cf3c751764a4c7337088087437f93e942
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:0b143eaae4713a45bec5fb4b4627e4bbc272741c7850fc6225757701749f2379
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:6206365da1f2fb818114154ab32ab467f46eeb6ae7d61f4208664aa345ca2f0a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:f96b0e19ee97d4f2b1be9e579a0a541f7fb4bdab110bb9a9a65c894b4b871edd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:bb82c309426eb6472b1c7eab1ff92205fd3f1f3827f17fe54bfa364b9b51e789
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:e8d328c3d45b1bb3067d68a09c0e4011bc3accc05bafb804b64c0116e1710532
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:8cb8bdccb498e31d8317bcf80d4b1d9c8b62af8b4ea487a465d786a22f3cc5e8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:6015c8a8452ca231c68eb12cbdc34cecc465099f292ff2480d38092a40c890d7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:eb3127af45d7c028e6e359172fdc0cf56e29554baaad46b35f636a1f2ddd7e3f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:40493454bf695c78c1db0c9d57f51196e32762d6a7f1a9a4268c2582a4cbb707
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:629b93989056cf2fae52ed2fbe3237e8a41b021204ee62b81c633db2b324f5cf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:493047611c48a0f68a6083548b4b024563a72dd5193aee14953ff13eef449bd4