Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.6-debian-fips-dev, 18.6-debian13-fips-dev, 18.6-fips-dev

Index digest:

sha256:92b25f4a593645e7aa056d262b7ac8d7c6e0b6c43bf58a80839b84a3be7af08d

Manifest digest:

sha256:2620a941a1527e77bfd27b559e2e54283aec8c46846ab9571f521c2e0b1ef76c

Size

142.25 MB

Last pushed

2 days ago

Vulnerabilities

1
1
1
2
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:d0ed359d8b42db63120c9a26dd016dfa636243a433623b0c8bee0f51ab26ae0f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:62c13e5b90c03d9b41034d54e682d1c2314f080d78975d7cb3ed3bd7c888201e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:bf601f1c116fc5f7bcd2eaf989acc9e7447052733f2cc754475a60ef61d76061
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:2d6a356f82fd821484283ef58e7d50bdfb810c7ed75a4e62fabdf1d5fb921f78
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:45c3d886268c22234a16b940faedebf3f843ec3eec8a4dbd0ac5f0e7b8d10072
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:a3faf5701ed3ec5b63a032d6b05ccba5be8cd5239b1e22c8629c659986bab133
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:faea61326821f29ccb60426c795ddd1b820657380808b7917156db641cbe341c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:05997a40794a0928cdfa27dd456fb0b85f52f47b2ab6e25be5f2f21ddf2bf8a8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:68fb333b7a0328ca86b123c0f6aef51394f63c151ca3f07e576a94f7a0ac7827
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:fa38a90f6b0407540eabe53182122330aa387b1cbc9627b9e2bb133d41fb9495
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:aa2eda7b3c87826292e0a513d73abcf29f7d2c2cd2818d959799043095703b6f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:f73a839baf19f2034bdb34bc50164800c647c4400997437f0392aa70287a210a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:21ec0bb985d7fabb9c46f07cb0038447c10f8a7e6b2da83da7513570a9ed708d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:cc6ee2637e284747e67910f7f994f5b1403856edb7ce15760998ed5cbbe1b0d8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:d682d7c83a2375be615de8462672c125eab09246cd9dd922fa7d98a7ef8de057
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:b47c87ccc5f03e179dde2b3beedb0e39d5275d867b444c618a8b317f5e929ac5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:613d4810cb970a5f1dd230cd00244dc68df59d5d7042100b627582667264e554