Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (dev)

CIS
linux/amd64
debian 13
Tags:

18-debian-dev, 18-debian13-dev, 18-dev, 18.6-debian-dev, 18.6-debian13-dev, 18.6-dev

Index digest:

sha256:f7aed573479683ac083f0568caf10f0d54ca1912df5a49756a4a1b473ecf1845

Manifest digest:

sha256:fb0af9bb9d55442c85c10bd616b1b5ec4e96c70afcb832b74b3db6e17ab0040c

Size

131.98 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:910fc437f0748b6f64f5c818983d4488e7a30c3c8d53c8807725fcc834046862
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:66bad1769ef8ca99a956369b22135bc7b7481fd912f6193ac17fe021691efcce
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:51b13e65eb95dece7a260fb9b8ac1abbc5259f4f9053800ec199d821628b81df
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:74c360e40d69a5d776f501b4f3fdf251aced5b2d6a09a8bbb5dda130ac5a3e4a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:f999ef82ce1651fefa6490d1f2877e70449e61f90bf45ac3a9549a24c70b20eb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:969d976f25feb215c0625472300d9f9694cee6791aeb7abb8806e39248e6cc94
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:45a0f355605b932f6671f822afab2fae486383e4c39972dc03f45519460b5e89
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:b6c9d343db537b522ede7389648a7fd23e3f863873fe8815197d6de43a425bb7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:a2c1754c00b1f910be234dae7ede946665948764d20bd504e440d5c746c8dfee
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:fae7edc7f0fddc0e46ee91d790afcfca2ef7fd587caf96546511a7304c3c5bc6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:82065e695db682fb4fdf4a7924cae8bbd57da25af8556e7621cd09ae5001654e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:c3483d36caa20629b92948a2d47125dfb61ec8a0c7a006d3625ca97e6e8c0955
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:37b3df23839100d994e5e83f0e877dbf8f7bd829b1089125e29d5718d2be1d0f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:74a4f2643c6963a47fb13a4033ce91ef0be8aee72086f705becc60b6b9efa694
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:e840e61d09ad900f25ffe3610ca5b017d798a435a6e6d469ddc1d6cead70d1cb