Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 16.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

16-debian-fips-dev, 16-debian13-fips-dev, 16-fips-dev, 16.15-debian-fips-dev, 16.15-debian13-fips-dev, 16.15-fips-dev

Index digest:

sha256:1bb9e839d16bab8ffae21904ce0ee51792cec38e6ab9b22f481af71ef6bd4d62

Manifest digest:

sha256:a571fdf2d96d3e1c71a231c675b1a5a3a841cfcbf69e52fb4eb57d7b3b44a039

Size

131.26 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:16-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:16-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:e0498a82d0ed4960becc44cdfd704a7b3a19b497809b5e9cf16da00c6474ba8f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:1375ec8ada0b62ba831dde305fbdea2011cbe44da87e8079a6380f14d69f1bf2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:5dadc3801e829150bd4635673bd2ce6ad407f0bf8ff521507b411ec110e6e5dc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:52f951a7813469abdff231e29718da8010dea29b13dacf46fda964b3fb4cb95f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:8f475926a801fbfb4ea853d5f7743d85e976f5f6aeb06e30148bbb54a54333f9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:98478b6654c3f7c637178cbd3deca14d10125533de524835fba6902db713056d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:7437a2bdcfce1d30e2159efd3694bfffd0d104a3563643d7e206fbbbc5a2bc87
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:feb2022a1bfdea90c7e27091627f20cab2b1b9f09dab2bcf08ff86d9a2ce60c2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:db4694a39081613eadce93dc4d986421a198282d8745c9276f7650fe8bff91f7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:db31c6e5dfcfe3d7e8798de39dab03dcfa47d83e0ea10f81cf0d545c59492ab2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:3e94639459200462b89a7ac408f9cd8e0d6bfdba7fef3914d0860860b9a8155e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:501c7e9c841a1f80b47a2959192a44352fda85fcd9afc8c0b3816cebadc3060b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:e4ebc9bedde9e225891cedde6febc61e091958f210e8e45d7de3e8613f5a5e8f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:c904e5b811d6be63b355ae82dc208735b5e32867bef1f1b08a77a1241c5903c9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:f008c4dab4437423170de03faa601194c19e00644db8491c18aa3599c0968fd5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:54e6a4b9970fec63ee78091d29e6347f47bac51d550f154d73919d1b04006bd2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:d23b2ea1fbabd654cedc435e64e9f5a897f91db87a78db3a73c311c7ab98e1c4