Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 16.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

16-debian-fips-dev, 16-debian13-fips-dev, 16-fips-dev, 16.15-debian-fips-dev, 16.15-debian13-fips-dev, 16.15-fips-dev

Index digest:

sha256:5238de3246be80d9916a0bbaed5dac3cd65ba8229357860a143c4e883ed7d244

Manifest digest:

sha256:c7bbde3cb90836f9c3b3c0665f95bbf24925f983dba781c11025031c5ef17ff9

Size

131.26 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:16-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:16-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:311e864b7cd817f8a03140f1fead5f309ca243202bee07352303a064b25930d8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:9bc3aaaa739162eb25860b1635498b817034d17bdf51bd2f4da1712fec43b0a9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:632fd85d86cd54d02798e00f6ee7b9f0a5b44c66ab804cab92a185de51cf3c72
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:3d1cbd2f241cbb307dbb2c26dd01e58a5f53a8e9a4b4ffa8586391384b2852fd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:75464d6780b35743db50dc7d8986eb46b897ea6f393c74b25cc89e67ede0b125
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:dc65259f9845e614f88b24acf2bba008207dec15dcb903e24c03c5328a0d2ec9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:a4d637a2ffdce744e26a561d4b7dc9422214cf0d50cde3616fef4407ce01c320
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:81673252ac3014675e8d60c6ad59a5aab6cba4a4186df21a371e4d0a99ad60d5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:141e3c7c42a92b4562da94b07124cf385adc250d12719fc613e046bc493b3e7b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:7cb2914d86cccc4e1346870f0a55eb9591fd4ba35feea87b9f7f2f77e1426a92
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:1fc45e4bdcf2ebf36c5a5294dcc54677cca66073dcc6cba09d1cb4b4c1776675
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:71ddb9d7c3265b4c5eb1189ad916521ab708bff0f0242e4d42ec24c0f7b1b6e0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:fdc477a6ba7a226f46afd9716894a5c9b63d4fe97c113eeb22d27bd7c64717aa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:ad2b39208d11fae3b272ad7ef316b6029fb2d86eb79d8646b50febfadc114519
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:7d50d56c60f369f611c4d162062f479cb3d2838a90a213e6e8e4eacf8237410e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:097068234f5e05e8a3233eea9ac138ef984eb574f87cf1076833b793fbc29adf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:67091a64a1b6c8a969a0b02d05cc5ba9a7f2ba4f30ed159b6d331064abde7092