Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 16.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

16-debian-fips-dev, 16-debian13-fips-dev, 16-fips-dev, 16.15-debian-fips-dev, 16.15-debian13-fips-dev, 16.15-fips-dev

Index digest:

sha256:5f5c74b990dfaecf4a198359305cbbd6aec7b2f48efd0cfbff00ee594f7095f2

Manifest digest:

sha256:fa3dc943bc5a1711774e53dc145165ca1996e0a660c3d29c1b6f27d786d7470b

Size

131.27 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:16-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:16-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:c77244455f3a4d8831dcdd598b90adcb9d0b2d1a443ab0bcd4d4e468ce516c73
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:cc2b03a6e99e39ee6bd32ad2ffc0b860e7a347c7d4b0d483696ea4734c63ff66
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:e8cb416b6868080efcda40af0fd183cbc4a78bbc9f5f5f5245ff6d5842c8ffc2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:9dac6d9cc1a56f110e44631ca5edda7c707bc932567b77ca9918246865664f35
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:618d16905b7de15b0566630f1edbe7f994abc828fe270e51fcc02df66921028d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:78ff0df0e176d62f3cf523ac737da06a7b078e124787d3ff0497c4268ac6f026
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:947ca4b7b7a52cb11fc236f66893f4bf52f448ed0e6c33a19f22088ce2c06d74
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:635f303d44fe066e1de7615a458023bed6cbda7879d12a6a17e31e4a94a954ad
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:53debab7c92d29c08621ce22ff52575f878f20efe6fb7057fab36105a93dfdfc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:d90027fb1dc7e5f81915c83197927e9200f5fd73afe515682ebd450bac482be9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:e1d33277f75bd891545ee34996e5fcf728c0e0f8d8bd7bd6489d716955354d50
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:0a7507772c50dfdb0023913795bdc3b89c6a44bfa41e5193ef6c7b1350354161
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:076136e179b15a3d660cbdc0c53a8c135131545e62878ca414e7b94767a51ec0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:b487e8f0d704a83bc095cad393dd14ee3436129cc0512638ac725e4763ed8ebf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:c6138cd700d5afcde5f924128deab33e9620e21cd1fc8b8712e85a78a83ea9c1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:6296d90d82b64c43cf229d8cf2f74e62b328dce8635f5cb8196d64c250073642
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:36b546b8c9903ff0228a1249a89cf8eb7aba4b8528191ecfee38a6e3b10b9ea5