Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x

CIS
linux/amd64
debian 13
Tags:

18, 18-debian, 18-debian13, 18.6, 18.6-debian, 18.6-debian13

Index digest:

sha256:f9af95af8393322816bdcf7e0e5d0be22187d2de43c2e56e66934f32ed942c6a

Manifest digest:

sha256:8130c29f6632a6bd939f9f5f97539f321491ac6fe3b82939805586005823bea3

Size

122.20 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:5451753ecbcdf2bbe75197cd0ce8ee5972182071479be628db0bceb486eb8ffb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:602c620f2d8633769c9fb820a97a53d5af05016bc375611616fb45cbce802baf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:f4b7a2a06806db06a25abaf300d9f989fc64187456abc044d285c408f80b6a09
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:758afb36211330a0a4d053345e94dc5abeccfd65dad0d9ec18a229c02b0dd0f5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:42c2923ca729fca4b911abe9accb47ec18bb533cb632916aef2c69c14936096c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:245784fed86b90b2e3609eb8101659ce385f58303852814ca3e94e464bb6c897
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:530cf1914cc952446ea7ec06c659a68378d411c32f31e93969d2b96439b5d0c5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:51be8d6e6058755523ddaf604a9215b571e507716dc678d992844846805f879e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:0bbed9bdbca140d99f28f8d41bb7be6616d0d260e6e7c19ee3ef28d91c41bb7a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:c95638e668eb4e5788c1e9b92696c05b248f30103a48966c2a6469f73728ae35
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:31637bb59972416400c5402c9fa6321b93cfbc69906363d77bc45ba55caeab20
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:bf25d84ecd7698ec6023f0d40b93279ef03d2fad9625f20c277ad6dc638d3711
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:6a0cab37337a627e8f6d8f757691da45a0010bbe052e2270c8dd91df729198cd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:a72272a98eec6df12b914947622aa5bc5f85b6243f9d5da71abfd4c2fde73bca
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:85120947c635f1d8ee76b8a1796870cb7f18baecc6a01f782d1c6448f6f2b325