Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (dev)

CIS
linux/amd64
debian 13
Tags:

18-debian-dev, 18-debian13-dev, 18-dev, 18.6-debian-dev, 18.6-debian13-dev, 18.6-dev

Index digest:

sha256:2f40e388810025cca70d41d764bac13e3edfd1f3b02fd4fc26b97fede75eb2fb

Manifest digest:

sha256:0df7c4eeeb60dd6cb1b61eba4b9035b055daabd84a9e319f0c6ac7d245278a10

Size

131.98 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:e687683f312bf52f8530e116a92216b00d594aee6b02e69f90639e67ee34d6f7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:637f5d5b30d0b03a287bff5474d41258815d6111d8d0f1b1df7009f7fb0a9dc6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:d282e3974621b5a312419b51bcd66ada0694fb0787318c8daa88c8cf2737973e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:092163e087d28f2fea2cb5c7b592bc93cf36e65b42bbe4e367d14bfebd9b8e86
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:1ee5caee81104e2ff7ddb6e2872659b31cb11ccb7d7c6e05de5929c97170dd51
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:c22ac03584d145466f6a65f03951642845b897086330b58a903a92567268950d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:91d02be427fe02a6fe9dfba0db4101ffa6cf4957830aa12933b04a6e6abb905d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:c3ebbac540acd6cb60663bcf8c3d04941ff732f52cf4e1dffd4b1c224f9ee536
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:71ecf2e449e7aae0c53bcdb974fc8324cdd20f82404dbfe87db17625043a1456
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:d4ddc1c9239fc627e39097e4d4816caa5d18693b3e664e2bd183feec47e65cd4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:c2251b67537f61b929d0c384068166b9a09652f31b647e4f01323bb4a883ace6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:913a35beed7611012c4933df6c380fd49209f77dff697c7983124e4780386ee0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:1628273259428b7bb65be15e77ffe631dfc10ff02bc9c52390b0b8c2538dd646
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:b072d1bbd65ac4c940b4660542760f399fbcdf82058fde73d6c0e75f7587159e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:5b6ffdf03f2900e61f1274797e759949522a39c68cb64cbf13683612b9a13f02