Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (dev)

CIS
linux/amd64
debian 13
Tags:

14-debian-dev, 14-debian13-dev, 14-dev, 14.24-debian-dev, 14.24-debian13-dev, 14.24-dev

Index digest:

sha256:1e0578c94ed26e7c0d24f4f2ea4ee995507c6f93a0d8594d20c7ac2a6b26aec5

Manifest digest:

sha256:a1a0919ddcd5bb3e6aad9e1de4af7137c7a56d5240ba2037a0d98368b260ce22

Size

129.51 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:8475f8f6fc83e00a0e6721c7ab57e871de2dfe3fc0935552b9672bea8b1fe4c2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:6592a6653bb40d1bc44e23edd0fbd554feb14a8fe16cd84dc97aad07ea4115fa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:5b58f2984771bcc554f80db3f5e00671b17a51c4b733418cba7bbe0b2e89acf4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:f7cc53b1a3d38430433cc818e192463f2a1d9cefcfd0b62a5efd910dff192839
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:7308cbc267fac195f7028b976497d286ff5884fa2b47491c421f3322330abc99
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:de667acd3f1c6b1d594ac8758c63927e58eeb97aeb07645ed21e71e343864da6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:6f039898dbee849d55a475a66fda732a167cbe0d65e17e1c14314b9e8a330730
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:81bdab9f2763f51eb3100ec1907179faf20c78c327ae12f8c5189007f27ec6ea
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:57b579622a3a9d699dadb7f3788a10ac68ac4c253d4fa384a69763b6fabe74db
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:c3b77adcf42f073bf3e282b10918c547c0a70e588db4cf012c3209a8e326b09f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:aee0a07b9c02115a5e7b31df2e36d91b2620911ce04879e9b5c0497b927d3bfd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:6af3927018bc97ce577f04591e96651db41fb7773e394f53a67a16c39b8dee7c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:a502582c12c3abf2c5d8b29b429c8608ccd44606cbcf8ad9d0a597fcda1371fa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:57ddd094908adc7b3cf71c68f1ae78234497b09fa3c4f468f959a6a20764d60a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:7d3a60ad7a9f02858de64c80ef74b00837fbce759bcec237ce8eb7ee4e831992