Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x

CIS
linux/amd64
alpine 3.23
Tags:

18-alpine3.23, 18.6-alpine3.23

Index digest:

sha256:86fa0de9f1c11925af0b8f2cfd4811dc528a9c318cc9eca39631bc6c0a723e6d

Manifest digest:

sha256:32f3fd227143fb4ce2c5ccf4e8c3c11efe1363e860956f04ed8173abd39f5444

Size

92.43 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:aed1f1ba996f5c146db4b6154074824ed3b02e193fea564ae7ac40df4695ad44
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:f99fa2c69aa859c15fb7582736e979dbb0a5fb680aa06e1850e1021517da9ff4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:a9bf355d64e2b0983a65ffbfdc9409d6583d3afc5ff1da71ffa8ec3bea19c983
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:b32a374f95d31360ff7ef5262334d678024a6e0596fa78ba64832ccc327fe72e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:f313dfa5983b59803139f5e222a67ba5f0cc5c7675bf1cb903fb012aff8645c8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:85858a0579b1ad1e261f3bf1983a718108f1a51421153d289af2221394303698
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:c3b170990cf0f7898d931500d8e41ba608e910a05e5c3e630e71d6c028955207
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:631b94fd89322187194758bb5b97dc458e3eae2e52e9bd67a91e2b9ebf23737d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:1926cdf4935a1ed815a8aceeb348e397652cd044d4fc41d1ceddeb16e977f25c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:0f9d38d2602571d6e8d40251a624c7b7a485ceb5954e4ba18585a1f29507a940
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:796dea9fa53f3c619b7fbed24ca6de88410d5df1dfba175655f9e49eef8c9c60
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:b99cf3f12256bcad7a17d022de2abc4223415ab69b5537711f1132b64b38f288
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:f5b03bdedab9111745d8055a7e1affd29dbafe194cf56a4b23ada83f86e867d5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:1aec96961114823634d31acd348b04dde123bc288110127b943fd16373ddd437