Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

14-alpine3.23-fips-dev, 14.17-alpine3.23-fips-dev

Index digest:

sha256:3874bfc610a8fafed31c6b3d62860ccae0224a0cb33045b9971008af672cf487

Manifest digest:

sha256:95399c727f80acf61b9234a84d67344ce8fbba2c3828de584f9eaf3a8b6709a1

Size

133.91 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:c44a7f121ed4318cc4f0cc4150690d517e487d0672017857d82ab68e796be76e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:009c0c58319170df740eeedaf351ff60d14b8ebcd6bfd803ea4adf8afd276fbb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:cf4d83351bf6fd5a68a530f553ec2e688d1b37d2699eb5757b4f0e828d20c69f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:c32709521a42a3ef1e647bcc107a73e930edbf19acd58dda4adbfc7a576847d0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:9a6d88b73b0f2af4fb23876c3e0a0b264bab9601cf245e4561403790817fdd25
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:7178f69d6e4ed3adc8f49ec9dccb570d20ce1c0c08ec24d6d17c9879323c1089
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:c88631513e085c2567fac937f9eec213aa94a9bb918f4a0c1635fdb99a51bf7d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:55d2e13fe80bdf876ff6f1214b9c1c747ea863598bc9064ed83cf48537c309b8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:b301389b1bcb3f8b4fe181ffc49309f92d9d9481a2f128895acc5e288f7336a2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:097115759dc5ceb9c1ea8c5a0ede2664f98b7cd625a0c61f6cc108ec9d382089
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:f3b24b460fbe51c88f38190d43a60527679b5e8e78fe2e166f3155858eb6fe8a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:5d02f11251b51afc2def5b3475e5d7805077a817cfd0db11a32487152aa690ff
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:66032421f27873390a557b5be8c1cf772403322e2572487ab57126b9445402a0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:7aaaf6470cdee16339a5338571135ff42fd69ca622542c97232128e3217ea1e6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:d974380ce5d34a2f8afa4ad72b001d38388425bf1fdcb11f869267c22005200a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:d70943943e621461e41ea10121c20a99f18cfef552768e7f8bcd474725a56e49