Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

18-alpine3.23-fips, 18.6-alpine3.23-fips

Index digest:

sha256:3c92afa27844f6b54942b5c46363b5525ad9215407ac2c718677876f9df9eb12

Manifest digest:

sha256:02da649049b8535e0acd81b4d2da3b61718c4be833b69d53c63205730fe7c75f

Size

93.59 MB

Last pushed

5 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:a5b436cc0882cfb73bd1ea4912d9e8e6e46fc647ea05a3b9d60def26a065621b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:985ee6b76750625feaed4f04c6388857b2188112e4648eda71e0e8a95a2125d0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:7384eaea59a6bcc4d8019a87708d76b4b3211fffa170e1e205cd775415abf520
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:0fe7d45c07deb1dc50532afce98df156f86d9100ea251939dd7b292c88197ecd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:ace324e6d89b1cb9c62f949dcad74d2ab9e7e92487602c9e3521fdfc63e4cdb8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:01d256d21a0a84ef6c273a647074a0f9d61946e51360f7b47fbe564934f1ddad
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:0091d71123c063076772def747d522d28ceb12f2bf5c4760f8258fd325bd1be4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:c438f7d712598c1e5d358ad0f7ca72f4e080df170600a08f1547364ee31d9cad
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:b4e317c5213c1d17bbc4c14c8cd5b990bc2cccb6a3dafd3d2967e4ed85aa629f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:268645fa6afe687b5b0fe20e576ab3331d82683d2e3bdab76c0907c423ba5b5b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:3e65735bb2d1c880e6ef9fb39804af52fbcbb9df88173311b0234269835a662c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:d6dde958c3cedb908b87daff661fb8431dd201dadeb45c80a4d2ff3a027e0c7e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:ac7767be4ac2fff3f8b995a40069f2132b9c867f1bf66f66edb31b1cda9d65ff
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:099279227ad9420035872b22305419796bbb58be5a336ae807a89c6e9d3e7aae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:3f21508b3c57b0d379d2e84854f923b6399c2dd9c15235f8cad7f89840aa0b87
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:2a4466f8ec3510f8fe5ab368d45be32e2e8b30499bc20a862eda83b7049b479f