Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips, 18-debian13-fips, 18-fips, 18.6-debian-fips, 18.6-debian13-fips, 18.6-fips

Index digest:

sha256:16cc8b411872ec711316527ec59577bf7d9fa47fbe92907df7a4d73f8315e4df

Manifest digest:

sha256:6e49ae195867ef0691c9cae1238469ba0722f7410a553ae14886925fd42352ab

Size

132.05 MB

Last pushed

1 hour ago

Vulnerabilities

1
1
0
2
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:9518f992b8bc471b612dda8538fadad10fc9869b215d3a7c5a1f158fc186c266
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:21171a7753c0491dd91343cc25b615e005fc0f9ba32768b51f96474565c8f9ba
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:09af1d96ced338e6cad90ec3731bafa330ca5b3b3a1c7818857ff4e4a23cef1c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:941e1f71524423a3047e99fa62322f48cfd27d17e158d9ad3c8fbc6882f2cf67
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:69382d12333742ac0d87422e516e97505d57d114160b798e8631630a0191582d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:80414a7b783bcf04d9631dabc1e080d6db600b4b47e8329b728075fb912a1ab6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:114cb9c9d4e8ec195779681e09d371f58da319b20a431657be7351d3d55de4bb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:ce09ac19609cb2fe1130256f99def9b0634cd4d70c45359f1b1eb6d4449ba626
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:788c1ef3e76b4dfeeab6875dbab0d4d30a72c1807fc8f88680579b3198fb73e5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:881bcdfcda09648d06bcb70e95f694e5aaafe5cef97355118db137d8edf7b6cc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:c33d171c83449e403728be419ac3bd1bcc665e9383d286ea7152da7878a6d2ab
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:2aba1344690b105f5f376625af0e16a16deb80432d4df2514c56a9a1c7c2d4cf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:b0a6be3c903cca5524061fd01e74df684d71ab06d5bc09723a7719cfa4b2d3da
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:675993e3162b74fabb84f742a342227b5dbeb11eee61a5cff1978ce15029081a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:712e91ed1cd37c8e01a7b9f6bf5a4f8d0ddade67a89615b753f0553034ac3e81
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:e1fb9a7ea615f155a45fe09346e70ee906a424c825c3642ab3f3093dc7f1ed90
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:3288e513f9058a8ac2ec27618babac66a8e6e67e6f0596c9bb7acb6331a7bffe