Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 15.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

15-alpine-dev, 15-alpine3.24-dev, 15.19-alpine-dev, 15.19-alpine3.24-dev

Index digest:

sha256:f1807955e7a7f9ae81fa9c0f2e701e00bfcd282f98864ad638dbc0017c04af02

Manifest digest:

sha256:23bd2564f71a5439bcaaf64b8026b609ead5c81c148e7d672297888956d5e368

Size

133.60 MB

Last pushed

6 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:15-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:15-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:60885af0b8736f3cb3eae6068ffef2fd815638ff70a8dc9f5ca2e9b95c8817df
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:898c90863d9e04295c77ac79a6b023ec0cc255803a470282d5abb44ab3efa005
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:9fe5e4aabded94325c294a19b27785271ee138de200fecd43ffbdbe2e27c837d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:aa94cbe4c36b24ff23b02b5e6989bf0a8004815a3fd6b88cbd15ee7a144d996b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:f7296db6adf823b7a5fd66436043f09143646a7945836a11b811327f85d3cd79
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:e6a0198de01799ac2e2e032cc7e457bbf3f6543eb96a165a26932ab8570fe585
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:6d81eca372f42ee51cd91fb9eee592cdc089f51c839d3889267df2452b9b264e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:0e87babd2be05759f5276a0425d28b6c718cbe7bc79b69ab4d8aeb8866d90533
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:e9f041ace79ad40380884fc68579464d30a7f3ce67e43d6ed13fbd38000452fb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:37d544e75d0d1a1833e6a75432f41edc70521802e938f5d472035339847c4b41
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:21c8182fb6828168dc8e649a7634e90eb268cf92525276de6232f7071bfbaaea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:0086b8d526bac7645add74583dde1497596342117e92f67e4f99ad4428c54815
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:738a5420b4af949551b49d77dc2734840a056de890318f7a8816e3b15f516f2c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:87dc456802c26ffcf5e13e3425ab38f02aa84eb99c7c2c47336a25c4cd6cf9e4