Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

14-alpine3.23-dev, 14.17-alpine3.23-dev

Index digest:

sha256:785592ea1de91ca0cd0af527d84f79599ac4363ad44669ddb2cca93947b95e43

Manifest digest:

sha256:33b549e6bf490572fcb3eeb4ae98bb65e7e1fd5f21deea94c6c86b1885dfca2d

Size

132.69 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:2d90e4dfd83bbed56b179638d77d503e1a5a996bc5fcc2d29ad00e2ec087d0fe
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:3cb4a17d45c09cd91088aeafc784ba653537d5e3882a90b7c9ab241ede602b9b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:a60126b092f26a13f0149ad87147cbf20e40b3b1407b9436d2cd13cdd94e174a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:79096813f2df90ded08733ad11aaeddae60c16094f6fd72a233be7c73b514ec1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:b14bd9dae900bd84bdbdb8c51f9a1f2a85e1016bba32a6037a14c201bf99f2dc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:0bc3507e0e1151f96a4cc3c343ab6f40ea18ded26430fe49198f510c2b2b5f1e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:c6db23725a036b1a277aab5c1ef9cabc05a6076dc9edde8b3f2c2302c5e001d7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:c2ce3f9b6bfa4f3d48882100231496023fafc263c949a5f851d0f4d1b5c2b050
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:3cbebf70993bd5873e3d151ddc6eab3a9746ad12ca0d11e0e8aa2e1ccfc6efd4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:b779702235fec558a1634a4e6bf6a454935689ce7a478fb9d0d2eb37dc01eec5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:10060ac8c021f0355eeb636ebe74e0ecd498a9457bd94fd9c57546e1f3eb7697
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:e57c17f7a19d141f42eea6cf98d98600e86d8b9226c749f19f91fe853bc8045d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:3b0efe0c0f9f9d564d24cbfe2fc9c3b3abc5b891c4dd191f9516d806f57dddbd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:a5c1f6faf8ab1c6ab6b3cdd2430b22cdc89d41b617fbd0cfea8705226c76e4ae