Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips, 14-debian13-fips, 14-fips, 14.24-debian-fips, 14.24-debian13-fips, 14.24-fips

Index digest:

sha256:628499de8a500fec0c595b65ac70edd5ea71ab5566f6838a062ff8c589f6f7c8

Manifest digest:

sha256:e03316da32394554d761582bd35004524436c1e291f8f2d8ebcdba32a4b5f3de

Size

129.51 MB

Last pushed

2 days ago

Vulnerabilities

1
1
0
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:af6432fafc2d2a7927fe70b7cc5e20e3c24e57c90d42d192b608678eb8d36fd4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:3ba3e212618945e29649dee148fb80dde17fb7390025fd3f69ae53dc06bb4c86
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:f231f4b5b79e74a233cd3ffa249736d169f06874041f8403804332219a2c0bc9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:1425893abbe6983af3712e96fb95b0114c91442127f4fc6c6c2c41373f4c74a8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:689e851079cccd9b9c5b9313a24839ec73e55e6c1665bc9430838325fe048b71
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:6c6ebcdd01cf7714334b3c600bf1dc4a65fd5eaffe4a971ee944a182f73d0054
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:e66bc8b0c1025c36f1613755106a771744ff1cec1c2505354ca74097718de8c7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:3da2982369c2d0be0d9e95e7170af0ba901847b751abc5d892f5e881281fa770
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:30f5ae986619373648ec048ff58efac7432df2efaa8baf35e13493d288b7e895
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:28a7379624e24e7d7608843cfdd6aac4d11e0ecc6498347fe6d8fcf8cb160041
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:e47ac315ad5b4d8288a1d68fb8e81cfc6fb40eb5f6bcb75a5005f1d0618423f7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:80533d2972e1d1bd9e1169479b94636ad827f4321d7fe809dcc4ca443052979e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:cd73a668d00b14d643d15a10fe68332181010ba7d55c839dbb932cca364be557
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:329d5b36e790816f745ef1f3dd3f326e46b13c9ab488a26e450cc73f9e92e0a7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:31ed3924e4b376f466734e19d1b86f382b85b2e9e7a909b87548b550a78ef3b5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:19c986fdca55c395f8be0cddd3a7d6cd39b488b62c32fc1b7b13f0789b3346b0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:7c4e6f4fdfb1c61e75b41234abee42d874f10e791230137cf171a6265d89e204