Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips, 14-debian13-fips, 14-fips, 14.24-debian-fips, 14.24-debian13-fips, 14.24-fips

Index digest:

sha256:84569bb835cffab07ca6a98d88a8f9d10cf92abf274f752a383f24b0d82667e9

Manifest digest:

sha256:d2d22a164ee04d3e1e7a391d3d4745c1df7e973a16487a0fe54ce92de787a89d

Size

129.50 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
1
9
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:2d7d807aba66e7f587b29cd9adeaf92d63581537aa181691bf05f15c6b2c4147
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:ed903f422290d4d77ce814f1a07b19467dd094f1c97116b790a9a07077d18502
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:e3b9eb473ce334936dc980660f477fd0b1bba8c669105ef874ec5c1ca49d914a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:113e3ad144494caef0da1557aa5322e1350581df4336f53a7481892ee793032f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:6e76142dccb31c5ac0139dd20311176304d62b0a2a387de4ed326a7203b607f0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:b798b00a36510cc083c91e4f87c7aca3a8156c114a00c5273c9f2d5a112d2df3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:7e0495582ab9f2b520e9a8fd791934ccff189624228e25fe9970bccfbda1e4b8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:3c1048d44e6f5b0c0647677fbefab8e9bfb22663e7459f80db4b13cc0ec9bcba
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:51e93dcf06bdd23c76dece1eeafe279cbff339deb6e994a33f83e0c1c17124d6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:0e210208232bd7bdcfad7e55a311defe3d0fcdd54ce54ec6984ec12334f34c86
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:de133008568db546eaee2dddf912b72b6f8f70fd91db9f82ba9471440a4015e7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:6b7417409daaf5e4dda1e2ac7abbb34de27bdc9c8c9469b05fd746bd44d5a510
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:869d251cbf32faf07f83f4ce8be5852943943c77440b2db5c6744d2e480d9ba1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:9962fdca8157ab266f5e7d7f9a7721994e5a8ea218ad23d6ef2b130dcdc391ac
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:bb8d9ead2c01bca04654d252b7318f19b4b7193861cded5eac3d81fedb61ee1f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:7ee989531e838b5d8e76e222bb63fe16552c70122b9bc735460017319f7bb340
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:3e8121f117077a2b66c71d53af7067b4009ca6d00faa913fe0db1a5a1bdff96e