Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips, 18-debian13-fips, 18-fips, 18.6-debian-fips, 18.6-debian13-fips, 18.6-fips

Index digest:

sha256:8f0a3d7a94dc6d0d508a9abf3cbbdd1199cd76c6567cf2866097a647183a5b72

Manifest digest:

sha256:7a9fa50e215bae9dbe363c299c455a24037d9d85c1c959f8bed381f26dcecd5c

Size

122.93 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:06585bc91d563c9b7b70742473e5d3bd57312d0e6859b9e6fec7310b681754e8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:37e61ccc7373c6dfeb6b428503f96c3ba81c697c74714ebf2c37f144fa687f52
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:fab009ebab58b57508442267fbfc0c66570b585871c2871a0fa006c64c2263e0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:16e8847ceb7dec9fe8ad1278cf3b8e6772151f182d61c4c5178cfd9bab4b8ad2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:4b1b1cf432ab821ab2b3ec43ac9b0710cfa4c0747873e65f5600b5245de1f5f7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:e24ab4907d80d32a2efedb0c257646801c71f403e97812ee66a71ac39b350674
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:abdcc3c70b64ba4335858c4440d31f20923fbae59fbf8956cbc39b4f62384081
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:54b458aafdf40657742cc89d0c2967dfefe1903b96372d2fe163d768b4c2cefb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:29b08dc5573086d67264fe42e51cc287005a7baf6becab6ea30b871fbafeee62
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:db8ab84e04c8ef081b37d9209035a4be33d145a1beece94873e86f4f2f87c29b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:0b7c2dd9ba069d96ace80d062d02761d2aa5fe8e3bd237825abcec66493519b5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:fdfa1595e82259544a97a0d2c80c32d56d14a8b7fd8f20db5b7f99dd30c33b34
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:34974f269f9cc67e973bb10d7ea5f35daef277e49970067edd88eb01fcbaf747
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:bcc2fdc5b1d041600a36eab730980893bd958cf713eb7b3ef77c40b63399a67c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:a2da0815761a858da48ffe03e0007dc6163ca514c9f7ced2e720182df328194f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:87788a7d512c1fa07c8a377f6423b1a05a56431c9ab44c389a0f197f813ecee9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:2ee038f344d8653d15f350f32d55df7216deb4e46f20af3e078e562fb47e72e4