Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 16.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

16-debian-fips-dev, 16-debian13-fips-dev, 16-fips-dev, 16.15-debian-fips-dev, 16.15-debian13-fips-dev, 16.15-fips-dev

Index digest:

sha256:0a5c2a0abb3831bf537a6e3e71ef7ecd3c73b3c2b0f9c4faf0d073a98da16888

Manifest digest:

sha256:2e8fc39fa84a4cf879d28efe70e1ada2fa0111d95761673b4c2d9d03e3c53e22

Size

140.79 MB

Last pushed

20 hours ago

Vulnerabilities

1
1
0
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:16-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:16-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:8d46cf8065f71edd1b3ae3a42d2c88eed713d31fc518a7151799a6b20e87837e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:ed452446ee1f66ba51cb011a5b57d897b625755fe88f5bc8b9bd789f17cc4973
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:23aaf099aad75a42b8aca4c44f293c7599b3788e75885ff076a294956005f9ff
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:f820e91feacbbe26f1bb583950d69b0471b05cba10df963be81fcebb88ed6a88
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:7ac14e54bf190b51b7c419c1250d4f248c529b7362c2181a54165625b1e4e12c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:99556a0e9b5c1b3546f303b5c84327213463dec1c9fb930381ab91d09fbffe93
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:7b1192b4a15ad3bd2be47293a508cac9d732701457faa08c2bd453fcff945adc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:c4eabaa9ad7c1e9f24e4a143827bd2f2cbf1f79513fb1880f7d0a6ad73c47258
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:46fcfc93239c88af5f8b06c087eccd03c2b67ae7d6f0e14ed7738c2aa105a492
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:01425de1eaa62130244dc4372ed7ea35ce7a9d5ea52a02a6bb9238b93c7b7a30
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:8fb99f8ffd9a4f535fa6026589b22aa5c9085d354087b9672d182d22ddce6f31
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:d9d8cc93f8c5e7f643a0be9ca1b54cbc27fb146bf96a04a51b58ccade3d7ccb5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:a06f3d78c583445eb478081e7a8b262c45ce5f05c240fe0e880823c613a93b50
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:53294eaa5af9dfd31a0bbadb0883c513a030092e60b8960129c5f706a8133377
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:fd9c908d692e699dcd0a502f09a082a37b8e837e346cae2874b8028acb0b7a58
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:5b67158fb81ddc4da5e3922f48741eb715b6a001a1bb295776120f3c88bd4de9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:0a1989449fca0e307220fd7059ba1127bb329ea1363f3ee67aa90e92304681ff