Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips-dev, 14-debian13-fips-dev, 14-fips-dev, 14.24-debian-fips-dev, 14.24-debian13-fips-dev, 14.24-fips-dev

Index digest:

sha256:cb13bc88693903fab63dd8d1e2f929f24f49fed3392a0023d417d5df4f99e8f9

Manifest digest:

sha256:3a1dd74322a091d79f4dbcb08b52bec46d7182119fad65ebcaeeca0264a7b254

Size

139.76 MB

Last pushed

4 hours ago

Vulnerabilities

1
1
0
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:86415fa2dbf2c4f57aed90755488322b8a5b49daf2f8c79f5b203ddaa8095094
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:2bc6c8109741a5c203ac65227453bc9702d0b3e7ccc0d7fd81f7896d55c5a4c1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:e769f6bc75c8fb29908c0b7faf001885c01e1fff63c68c6d0557a60d3f891f37
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:0cec88febdab9748cd3fd52c585c3427f66bb51bd5d2966e936fb7041ffa5427
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:8de42a25944b3dda9be5b3ec15743389fa65f1d8a619aa25e41384f151ae5af1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:b81c50d111c133cef622a920b0b10c7deac3d26c7937f9f73fc0ec9a8e37b0dc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:c75d4bfe1b12ddcaa5cedebe60236a0f10b92754f236e5e3264ed2e765ec6031
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:ec51b478932a3aae4b6969784073fdac6be72fec2b6010f3d534e29c0a941a39
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:c5dd17f612fcc776f1e11ede06437f16f76afc206522b13893e1cff98051086a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:e3299622375dd2920f66cd52d2c27c3a69a2426079389e42a6e2f6d4eb38dd2a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:38fb92fae9d5b101d9879e2180e82533827aac1f63aecc02ec8bdcce65b0e743
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:e1b206cdbd88eaab5904ee6639d7dcab6cce25f2f86e1fa89191e3fe88df3847
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:6331637b5706b24324384ee57d3b796a2a8498b6c37dbcd99bab71b3232c2d9f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:f687cefeef3212953a2c08f583f8b2692e55ab880a51685df5f9e00cbdce36e5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:4b4df41bdc59d8cf9fd06530838aff14ac9bdec2a7675964553962380cecc301
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:a6f9c190a725924b8c8de551f2857b622e9b62241c0e789e17a27d31a4a738ca
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:13b805f5e98ee01c9bae31b9892e2b1cf91e532ff7948326b919268fb2fa0b37