Sign inSign up
Postgres Operator

dhi.io/postgres-operator

postgres-operator 2.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine-dev, 2-alpine3.24-dev, 2.0-alpine-dev, 2.0-alpine3.24-dev, 2.0.2-alpine-dev, 2.0.2-alpine3.24-dev

Index digest:

sha256:b79c185377ac264cb92e3002a9d9f58f7c0569e38d1c3429e6794195721e2877

Manifest digest:

sha256:802823bd1cf16697871d72e9fe166b675c0c4fe83f92d88ff981f26989c26c5c

Size

40.47 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres-operator:2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres-operator:2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres-operator@sha256:c4c1f3e4de13d75bfacd9298e6decf338e362a3d8b1c029c632df3f3f16a2c0d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres-operator@sha256:c38b9325a531ad1e5fa78cbb8c704cc5aa3216bea75dd1edeaaf5b58010a66fa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres-operator@sha256:7b3e59771de427ab5fc4b95ffa3168ca36dc66e4962e2bda1ad279a48ccfcc56
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres-operator@sha256:a56111632727bfedeacf2b286002edd2de92fa6b23975da7eacffeb94ab8cace
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres-operator@sha256:edf3b054fd0f5271caece8f13eaf8105d3b9341667579b726270659252fb61d4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres-operator@sha256:aaceab504173a2eb4ca46c55bb9f025c657af9c9f768a6dad0544b00495c1639
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres-operator@sha256:0447c2a8ae67abf4c9b89fedbafcaac8a0dc7adbc270987e92e1e654a91dc10b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres-operator@sha256:7eddbb04792c2bcca8657c393f3ded49a2bda4cd9484260c1ed13337abad47f5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres-operator@sha256:664437a02bad72707b2745ce37294a9a3aa9ee47f28afc4de2aa5b3a1fa8ec7d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres-operator@sha256:535b384c43f44a3135f8710a5a45b56eeb110569862ba57da1d44d5a08495dec
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres-operator@sha256:f04d52579c9bd87803a4c779c68c29b58d2d61d3ba76281b4933b396ac04b299
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres-operator@sha256:466b962be00b9f17c01c0a7b82c02312f21dfb7ae63a658060c51b08e1cd1673
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres-operator@sha256:51af239f936d5c77c2f5fe1e7be1a8e5bd29a4e708de7154537cce62808fce49
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres-operator@sha256:b9584166bbe28b3692087f5fba4af9e9369bc802893d184ba1ecbe4381c57968
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres-operator@sha256:3fd9744bc23a36a9989565388f674bcdc9e19abbdc01b2c779445d0b0c8f40bb