Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 17.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

17-debian-fips-dev, 17-debian13-fips-dev, 17-fips-dev, 17.11-debian-fips-dev, 17.11-debian13-fips-dev, 17.11-fips-dev

Index digest:

sha256:046be96d2070bd7dc7a1532f1dd0f6749b73cf8f3e77cfd3ab0080a5a410b7b5

Manifest digest:

sha256:0f7d6a022b9b73073654b63f76b48899b4f29f275056a1a584d21c108650814b

Size

141.53 MB

Last pushed

17 hours ago

Vulnerabilities

1
1
0
1
0

Support

Active until Nov 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:17-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:17-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:0ab0b389a7f1b781e2fc152f6a4ded7fc682b658b343cd4d297073848385ca00
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:73d144df68f5a667af23df75eaba7d615434cee63f8393aefc731b404dc69cdb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:92bb008f21e053af2c0f8f4d3112767b6bfeedd64b86390e0f21607451bf5650
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:e8744496cc370b47af17b0543048fb37168beebb45e39a59b20c3e4277a7652a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:98abe8a073036172d60d28b92839f04d66aadfdd121a9505d16e5acf045d8fe1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:d866cdf2c77c12cd4424396ff1e2ce9cdec6415f2b636de28b2294f9bec4e888
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:fbb1e646ef6e1f64d0756ef404b8e223c00ae56558ee98dd23f71dfcc5790d73
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:c87732786734a0da6060ffa3a4c84736f5c6c82ffd88edc2e3f2d4a8ba6bf710
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:4ceb35530026c4b765971d2ba2913f3fda9897fa41eb0bb6118f1906227d012c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:2a083b801ddd9d1d5946a89598ad992b1615f82f2e654e01eda932af461f752d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:cabba9897519a0ab27cb2a97abd7d622d9a13cad4fd0fabd03589d897dcafcbe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:84bf669b50f8c36dd14b34d67581e0bab3b467851904e091f79c2e5dfd43e4ad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:69d2c7d1779ac3c63c98c5f2bfebf3e4f5209ec18966a0cee74e0608af029a27
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:ee479a38087c2569adec75c9e1f0cb6573b330c6e17fe5bc8c4a04088f1444dd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:6a87998575eb686b1e3272313fca80b6222a0f2e990bdb5d6ac453bf53ff645d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:e8413bfa5b33e8a602efd9bcd0948a2c44458980b3b3ccf71d1fff2cc57829ca
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:2724668c88ed7183728c5c6b9a64b1fc1fab3e68bfabb7c30ef8e0b5c6db942c