Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

15-alpine3.23-fips-dev, 15.19-alpine3.23-fips-dev

Index digest:

sha256:871480bd2bbe40e271566752a5f656fb3b53b198d45d09d9bbe75af1c7eb1932

Manifest digest:

sha256:bb2b9e1d745ce6cf1445651bdba0cf20ff346f031ccf34bc8601a57f5e8ef620

Size

134.41 MB

Last pushed

5 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:15-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:15-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:fb0029f8057b60a78bf42f4cb34411eb85e8f694cb4ad5e4ac459fe1a0e4bef5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:7879825bacd10e91074a87ade87caf442e2917851456ce7e0b77c6cc5d2ba515
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:6e80a57509dd1b8533b6f0164568a21d335c2f2ac0e1771fb2a02ae52074fc7b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:9b79761767353a2cbd4bf1b957a2cd4cb350a1dcab85998c4004797075b5b508
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:753530c948e3ceae1fee4af3c5ee4c31065cdc18ba8698f145c48c5c7a726d9b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:866c0d8bbc9f93440347bac4d6f3eafdf8e9d2083760474ec31e43f6f841963d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:1e2e3e575464b17619ed57fe78307905dd716e8a93f509e4aac2d1a91f033990
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:0be5d2397bf57da858d79318a74d571f5289a523af7ed6e2d765331dbeb84788
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:d1166df8ed3196d7b6c04c1a29ec44fe4eecfe3d266f5592243a627b6e9a25a0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:31f4d285a15cb473bc9b4e83a310b567415df647e340607bf53158efc01e881e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:7d892e9f2f514169594750f33eb14268827c635bcfa637914eae62c3af93db09
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:755ef62a14a2b439dc4c567fcf4da5112e5e06e9a228e5053c869fb9043ae347
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:8bfa670d391287d00ccfc3b20b8ff4fa85d553290b32ceb1052c19002980d1da
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:db50cf47c951332c23cb0eede90f102395e62e2e53869357eeb2ebe1fbbfcdff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:c043840886c61cd570cf3579f4eceba9fdb5b7ff4a6776c36e41d7012c95a057
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:06929612e0627d695e6dbfabfabed49c18ca41a172e856108c6eccb5396badc3