Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips, 18-debian13-fips, 18-fips, 18.6-debian-fips, 18.6-debian13-fips, 18.6-fips

Index digest:

sha256:bfd3a5529dbc0dc87cd117d055bfd0b0e1c07fba1256a33da8d54fa4f79f7bfb

Manifest digest:

sha256:5da26b81c7aa6f33f5eb7ff1d3e6d5fd1abe526a93a897dd38ecb15124a88f81

Size

122.94 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:8ef6c4da4b3889c1ae830027f88acd730f8c91889a3f829624c71b592abc71b2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:faf9c1f9061e4446a591d30374dc9244255cb2bfe18f27f7a3021e57bdf9da41
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:0fc2f94a6cc6aacd66d7809beff2294ea7e5a23dcfcd975a7c7569c5f6f9ab9d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:838e4591a7e327ffe542979c72d9d536d369935447cf92c25798ca77e62bafe7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:f855723c97919fbe99f42ecb1d4dff72c3afdb4229aa33079acc5d98f2097816
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:f17031a9da617ea00f644ed061d2196bee404eac09ab82dc35749f623820b445
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:fcd07cce606bfc63a31343346e31d81cdd3f96bf94d22dd2162452e985b59723
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:ee387f29e3d0aa821148d93307b466e77ce35b9ea5fc5f658f948c91d085200d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:9fe7b7fc355e079d2415760ad0c5fcb19a6c9aea62c6239062a939d8893f7318
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:bc19dfd9f4d45786971049b4e6bd5c338198de39c8e085a2cdd6e47637ee3643
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:4293e5e9269deac875c18d19ab4c1ada6dadef0247feefb5cd60fb83467c04bf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:d012ffe9f2643c09a4cf32f8978edee14e3bcd24be6836196e9cce2f0641947c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:a39fca042a500ccdfae6ad021926405b1ce524a1184de8e97f6a4ed7c480587d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:b6e661805a092e2f9d2db8e21f02f0fee7632bdcfabbfcf729b59bf8fcd445cd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:5731947681ace5d6bfd16548db49eccf9ad10c8bcae5bf2240049fa3f4d9516b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:8da0977391be1ce4cd54154248eded382bb901448b8c3e89ead1233e0571a796
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:dbb11f4c9912def1f6e668394b6310af9d06bd14389a1409ebab26a630d79912