Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

14-alpine3.23-dev, 14.17-alpine3.23-dev

Index digest:

sha256:4217463876014b73898f70e1ed206e5f5704f2147032902dc6869d0ee773f281

Manifest digest:

sha256:8129eff8ffbc74b461f9768cade824b743a51d237fbd2b26e15f058b78af1b40

Size

132.69 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:90fb5dacc0d41a5940f5e2f38a9c36e5090b3310d7a412787bb7629342116355
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:7264278011f7a2071fd7a213f0ecc8860237857ece322ce8c78db7de64482ace
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:9e1df31cbf02bb4e21cc5f5ffcd019611946f80a93bfdd28e3e8762a420d7390
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:55c36d7e78afad798a862161e80542ab775496a627d3d4599900c902751ec318
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:27cff228c96cbf15615a2960c72c7ebc06607753076276a0f7a15c7fad5d1110
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:5a7195562909b49e236976e58f10085e472195ce7afd36df1a4262a0d8653e66
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:b7da58f000f024c8829dfb9d2d420b85939cf241823f511094d8a971c6fd31a3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:eacf369eb1c530922f7da18cb7090153169805f1a8ebd1828b188c549131116a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:e99396d66ca078415bbdf4824881007dc4210e6caf1c9d792a8c440f0800aa12
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:9f62a48fefaeb80b9b218dc68d9e82336e5a8539def2e7d73649d858302256de
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:6bc955ba5a66bfe33d100e2a0bf393ed2e6c4e959ffec4f17be7da945d76164d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:e178293abe3aa62c90f56b57f5a223800392439935924b0a93d9ee1a440932da
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:908e935a6ecc09bea0b2737a58285546ba2ecb3bbaf3c918fda87212713feb52
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:fa035d64baa1b5f14c345403e88cbef839aefae1862b1295d1a4dbeedfc871c8