Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 16.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

16-debian-fips-dev, 16-debian13-fips-dev, 16-fips-dev, 16.15-debian-fips-dev, 16.15-debian13-fips-dev, 16.15-fips-dev

Index digest:

sha256:76b866a9297b41b4dc5eeb903384a47175753249f776c521a36e6537b21ed142

Manifest digest:

sha256:73817a95d2c43d80c1750df81c7b22de69f6494cea4255a04e9d1fb136657516

Size

140.69 MB

Last pushed

2 days ago

Vulnerabilities

1
1
0
2
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:16-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:16-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:80267b37f17f5aa534f59a60d7f9eb5f685d8d4c885bd0c744b2d14dd8ab641d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:3e55f132f2c9c500902bf827dc632c52b3f9d1e0b509ebfb2a29da106a5e5473
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:1990ce330d67c5ff9aa4b7a87f85b83139b6e55a23b40589e60494ba279bc8d6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:9823af3bfa5115c933770e5c1f1b4b1a1a2ed5d5ed74e3557c8d147ce20a1756
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:247728c45f9697d71214a1a0e4a83b5577d5111d8c4d754f7cb048af916a44b3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:253bad79977b000c786c6858572a444b9fd4b8cb98ce3f5d97a7203542e57f84
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:42b36020c89a9f377c440b249d350ccf28f99c471a4ba80c4567d10ec14cd9e1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:dd3168e792ab16d8c872f694d26926d95b4ac0ff35eb26eefb5d8554f1c7d2f7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:6738891286902e03407700a66b34b5bc57ef8e139ee1a15075a81666b7a53845
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:0aaa2946d5324630e306bc08125995f565203866ee049500a330e83b7b63a2ac
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:cf3703d53351ddb631d36d87a3e0adf1ad4e2388739503f86270f66af4247c8a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:baf0af0e09e79db61a06d6efabc9e06fb8ec83016afa9c04428deaa3f18eb6af
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:146efb6606b30dde1bb62c92cc514870f964b96f65b56b43ce8791a87eeebf0d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:aaced1e7748530bb39fe0118635ad4b94fb64312f97d7fb707663e6614dd644b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:017af3aa96df1e2354c9363eb6ca43f10c88529b840c814c5fd6de48e7414767
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:a57282ed7dd7543215257056fd5f9505792721ca6383d15c922904464219e56c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:95569042e2b0eaceffc0acaca174a1e24b0c725057e5ac4f56c02f43f42dcf2e