Sign inSign up
Postgres Operator

dhi.io/postgres-operator

postgres-operator 2.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine-dev, 2-alpine3.24-dev, 2.0-alpine-dev, 2.0-alpine3.24-dev, 2.0.2-alpine-dev, 2.0.2-alpine3.24-dev

Index digest:

sha256:e846678bb51c425c3e2527eeb2fb2d231d904af4fcbdcb806ae944738ed62355

Manifest digest:

sha256:92911f8138f1014deb8c2cf2360d2a3f092029991d1619fd885334fa05530454

Size

40.47 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres-operator:2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres-operator:2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres-operator@sha256:a9c5e53d820e4db0b02fa0500c5a098697b53035daee2b78660aebdd17bf858c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres-operator@sha256:126807c5e5da6b6311b93d782f786367b0748b8afb16f6b4461a739ef3eb7cb7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres-operator@sha256:19cf95a800cb88565629b59ab15473ca99be5d04f077513ac9f22c890d115dc4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres-operator@sha256:4bba1bf11294048619dc4ee448eac26f0685b2a6b45745bb82ed10d13f203dad
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres-operator@sha256:fcf886fa505758ada71d9cf269149d2c052651abea71392930ec0f776ba37179
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres-operator@sha256:0a31fd3a91770772d6d2be55962ce1e57e473fbe0bbc3059451d0f0296acb0d2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres-operator@sha256:aca78c8f9e70aa2b9f2cb001a2f2876d605cf996aa4af07bfeed8e07a5d54df8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres-operator@sha256:cb79e211ce0a200d76844a6a4a9cd1a463ca983f4e4fe7607dda296fbfcbd13c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres-operator@sha256:ff9495c52f5f78efb2f032b522876a1f0081df3c47145894062a34891627c04d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres-operator@sha256:2d28f1b60291121501d82555832856a52a4632220dad746c8b7727d9d17dbd26
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres-operator@sha256:9e211581887846939214080545c0997b09bbba99f537abdcd1bc24efd36a1bda
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres-operator@sha256:3ae19fe4d834d57da5d5e0c75a999953053979686b4222cf2bc080def2c066ea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres-operator@sha256:359ded1d2c1403e0e1c80197984c02546e9b4d4be843e3667c7c001b8c4df223
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres-operator@sha256:d051f53f38894060d7f1fca2c1d6018cbc41ead928f8b2158f7af5494b541ff6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres-operator@sha256:2e979ce38de646b5ea8b07abe4b6c0b70080bd3c404d6b6449f7dfc399602996