Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.6-debian-fips-dev, 18.6-debian13-fips-dev, 18.6-fips-dev

Index digest:

sha256:ce5a541f1f3776c802e839179a94b101b057a6657e74f3fd5d2a1d273641cd28

Manifest digest:

sha256:0904e2eef320a18ce8c0dcfd87c16634b638eafdfef00b0be4fc0c7b2416f180

Size

132.84 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:492aebf9600598bac9e1560e3fe0454a0785e737e1bfd92153a45ec512b6aab8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:bdf3693b67e52c3fb630e45510a045141c28dd4dd9981f7572088bede50429a5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:24458b5b4781ae9bc3ea4578fd98ac67b3447904c5a9f2861fd542238b4af27f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:a943cd49f61edaf8742b5437a1bf99014fb5c11a7b74dd89f971718f6b8f9233
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:0d371cfa47cb0af53aa3dbc6529fa4ea0ee9d1020bd8c265b6049f87c2a3b9a4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:13e93c747406421f79c3b46c26801f52c7d6b44ca15ffd5658924016ffdc7c1c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:3092fc3318f0aecbd908ae77726eff9dfb8a7d58686830d15affed04ebc2fac2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:fb5819b5a46f3859b43d45bb4cd21de9a54437d2a11d4b62d25a4f6684c00656
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:d373388ce05134c0df08b59d6bcdf218a59bfa70e605459d80cf866350161863
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:7b2451fde1665ba910f7873323081e953eaf012dfb6aa1ab566338e7ccb7c049
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:de23507b52b5193564e5366fd7cea0af442a779f2fdf15fe08dccdbd931eebf4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:bf7fdb64ce87f4e01bc9e898ba58849d074dc2d881c368270821b840f7b4a8ff
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:4ad95700c73270584592a6b4f4eddd9b1d01cd6a6201cf1067893fd89a3d6f61
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:013141669d8529449f93f2320ab97327cfb03c80f4acfb73a4c089d2a6aa8343
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:48b0e65701f950e2a1ee7de28972e7481e92cee659ea71e99ccbf747055e11c1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:411a6389189775cd9c88018eb403b9cca40d6acfd361e5fdf29a85421fbf6f3f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:08f3f132fe61dd7c3ac73994c3f6a7462c231867980faeec0cac6144fd59167a