Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips-dev, 14-debian13-fips-dev, 14-fips-dev, 14.24-debian-fips-dev, 14.24-debian13-fips-dev, 14.24-fips-dev

Index digest:

sha256:8224a859bc87f435b0bac722204d96b6c3b066e967ca7395b69afbc0d45439a5

Manifest digest:

sha256:56656735b5d01610b8958c2d282adc2131f961d689f6eeb035cff5d1b6d0ef50

Size

139.76 MB

Last pushed

4 hours ago

Vulnerabilities

1
1
0
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:aa27069ad3d185d30d6672f24a785e9ee654716c822f776948cfd04fa47718ae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:df8725061eb2caf3d1f87d32990d8805c973058de4ad0376982de48acf6643bf
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:5c2cf8d75a3065869fd2b5c68f53d6664de54bb37d5660ec7b920d53c6bb58ef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:54ff2d6d361fdb71d36e6b69257dc9bcb1f2b532ecc6e11ba920775420e182b1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:96dbed13bb8687f8dac6c52656dd59c56224086e6f4bde3900f59bdecaff50fe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:9da4bb23ca51616895f49fcbb6867c789fc37b558e5d7fae50f72ecf46803ea8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:c761f9eec7a460fda927928dcd15d0023c50a9e9c1a437d478b10bf9e1e2e462
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:f83d995424edad3c823470090bb1daa571af2530bacde2d81dc3cc13108fdb1a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:f317ad12c12a0203ab44257a9c746683f7484407fc85a77bb5fe5a6f22224fe9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:c71c31983cb24f7d048697434621cb297ae8db889d9b214d9619d2cdad4cd349
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:bd745ca668b5b916a0900e3d8569383dcfb360e5925eca91bec45f3e0e4e09d2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:4f453dbcace0f330e21076c7561266c9af36b00db04a42f415b72c1a79d71120
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:cb3d33c91945622bce9b73386b2e767f5473c3779642f82dc8f6a08dfec9818d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:eae6e40edd9fb99fa428a064fca195dbe3dc8595b6c142454c665ed45956fa01
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:4b8b52172463796c9cb01943e438fccf5bbbcfc4273ea23cac3446f3b42cc726
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:abcb6334a6c7d9e93690a69d8a0bc7a5738969a5ccb364ceed96413429af796b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:20e0bbf787632b8aaf8ba942c990086663da287b9792ae307705ecd928b59cdf