Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.6-debian-fips-dev, 18.6-debian13-fips-dev, 18.6-fips-dev

Index digest:

sha256:c9423fdfbfa3a5466b56c6e3674d0d6d581644cc20b67dc166b8da8c6ace8f48

Manifest digest:

sha256:2bf2aaf4b61f052fdcc1c5b619569c6420941c6e67e732c7836d88558ccfd80a

Size

142.25 MB

Last pushed

9 hours ago

Vulnerabilities

1
1
0
2
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:4cbd498500f96e3406745f304a9777c24bf3def4105bd2607ecf6abdac51282d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:e392fa2eb3305d988611f310f5af4a56fd0b7af73a0bd242b236efafae7508a9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:ce9533a1dd4c272a756264b7ff55c07d4c8179a258af02bf548965bb7d09e223
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:edae8486a6b6d17ddf4ba98a24c57ca1769d78022c9e5c3d33849d95a66fb23d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:6aa51a0bf8b27c2c46fa0a3d8274d96089475f5af9d01cc07bbf6c285ac9eaeb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:7ce2d8b4e07a5d16c7474085b42749f53b471fdf837f738bf5f1b27c31e4d334
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:cf5c53f9a56da9f012d82b21d95e4f2a3cc0b246859a5ae924b0f96a980a25df
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:c448e7d42c2c3bc5385c386444bcdd34d5f5a4a4bf2134e177e34b7c572af2c6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:a4d31622db19c5cb3e161b13958d606c5312a1283fe80652a9a6960b4045244a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:3d5fe0052b62d1728fbc433c2f83668c2d52c2e03b5df34bcd43f90b3beaeb2d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:469e7ba29e4f38642a8e9ad9b429d3e87da9fa513f1d9716cc01044b4c6b98a4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:c995e0c1caa930ea94149275dfef98bd720cb936f00b83c844783d32265fdc61
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:34e302adec2848b4fbdb3b4f78a6c12a50989b9c684e443e5f6dcb2f5a088de3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:eec2e6dcdd790e6a015794b7423481c6e3ce0a24a20a60116c9fa8213f8a2bb0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:6edc5e84ec9da323d737975e42378495f19d752e3345ff965ff927aa6c2c55b5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:778a2b57b8af2fe395f8cac3ce1b174347d08a4c4fb01f8b4b3824414a867c50
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:b3af62263080b4696c0056eb2e81c1d867abad9112e8037160cf188c86e16a79