Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

14-alpine-dev, 14-alpine3.24-dev, 14.17-alpine-dev, 14.17-alpine3.24-dev

Index digest:

sha256:52ddd06154b8a6b35a0ebc60f4979d292a6930048362ad6effdfd913038417a3

Manifest digest:

sha256:f1ff2e6f9b1728226c89ea526a5e0f1c37bbf5c5ed51369f949fd92d8297f8e2

Size

133.17 MB

Last pushed

5 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:2c9a481544fb4e8eff4b0167e1b1c97d8cdb9b2070ba39caeb69e430fb90d5b6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:7da3d29db60bf49f4236ed108999f41f17f43ef2c979638778435aa9ee4b6030
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:8bae49870ae148165b14e131f98315160969ad380f0389b184fd33e2566320a8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:a0403873b36a62e542ee26f1b1528fd60b4eb06dcaef61e7e0901588530cb18f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:02ca02e84c0bf02f3ade3617992b8f51f1f7efe4592eb6e5e483a16b03a2e272
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:82345857189794c0fe420c20c08b680c352ba44e503e138fe68aad8edb0723d9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:ef12e92d4746751309f8839ce20cf30d11fafecd52bf8a2f99ce001d8552fa15
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:40e92a54c185c90782b6118a594c1111edc702b37b9fc726aa123650a8c6d037
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:9735ab719f85b7a0c884210f5ee3ad5be753715e88577654312b5e22d9e7e116
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:74b540ed3854da72075298fc194b6a0e71812863ef305088c89e2c5a1d75e0d1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:9fb174643eef9602cc8053ca63c6f0ed5fa9b41d2a832b377f84ef83e98dcd31
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:9a3c3ea58ac8289bc12d636f74750d7415f1abd52368856edb0b8e282875088c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:ab3fc9c357b7089f532d96dae19c2439cbc7dc488f2734c62d47190435f7b30f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:bc496437f4a0553f71bff2640ea0d61652073b72a46850d1e6e102475e2c8bdb