Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 16.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

16-debian-fips-dev, 16-debian13-fips-dev, 16-fips-dev, 16.15-debian-fips-dev, 16.15-debian13-fips-dev, 16.15-fips-dev

Index digest:

sha256:341ca4f6c6fa6671d6f267968d3d42ffb2916125320b62d5419b0fc2715f5773

Manifest digest:

sha256:6dcfdb97daf2e5dd75f91cf6e8db8b810a41191da7af32f434d168e12268c2a3

Size

131.26 MB

Last pushed

3 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:16-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:16-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:a4e945fabd61079c27b274f022b00a322499ddc67f0610901ea403a227fe480c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:87e0706b98838e80bbb270c41efa1ece608ad84de7d8ddb4e35df8490e3bf7ac
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:fcd241214cf32e78ffd27c68d3361ee97cd9690ef0a6d9e5a089f965bdc0377e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:8a64e68f1afd8e10aaf6440b754ff237ea834ff6bb82e3690af98c1f1349476e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:0b2bc88f1fd0d3c7ad665f9e808d20c58b895f90ad2b0eafbfa4b6ed3f41f3a7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:900dbed8238d3aa1caa9563c647ee72859b61ad3f3869ef7ae1d7bdb61f64a26
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:a71a7caf8635b35249b85f0a6245afc9a52dc9c70e6290da104028c3385e1eef
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:959eb57dd12f18f91f0c7fe770dd49cb332aad0b1cba759f25b200fb4c3aa71d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:1d061154c82dc8c549308c463290702f37f477d8198b2e7d387fa7446b4c9555
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:ce6d02cfd1b8084e853ca9d067bc4b76859f3d2e01f890fadeb9fce0097172a9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:5940bd3432aca3861b5595e0d509d86424dc19f2dc786babc5f692dac2f438d8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:ed9d1f1bf57f570ef0f2377d1378dfdbd6676000d5fb2617efa66bea6957da91
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:b34b300a2b066beaf55d342992e5d029ea45dbe4709d0353c0f9db767f063114
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:645643f3646095c2e1b630d331988e62f658badea22eda1a8e9ac525aa9bc781
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:b318859a17b28284eb40f0074ef567755bf258923844757c1ef33c789fa6de6a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:e8b355545202b333779dc5d8cf49ff915a405be66d7b9c29d2109a4d4831062e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:a955962aae848c08f5609cad87f1f745e6625d63b2c9f6489c01a1bb43d0735a