Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips-dev, 14-debian13-fips-dev, 14-fips-dev, 14.24-debian-fips-dev, 14.24-debian13-fips-dev, 14.24-fips-dev

Index digest:

sha256:af68d67456503fecbc29ba58970adce950d765de6bb4215866bbe043c440948d

Manifest digest:

sha256:27e6e88d240daba3761cc63add504559804f0dbf042124e45a28562b0985382c

Size

130.32 MB

Last pushed

14 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:34d9a1fbcf2a712bc084321ad9a2200b09d594556de1f83a38aa8a15f85c299f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:6dd335ab536f44df3fd39cd48a0bd4e73b6a084a0f700099c20c1afe3d3f20c8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:c61111ef5e30b1baf8f7af1a7540cc2cf00106a516dc408b876b3ef79c2c171c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:4f9b49c3bde0996e79605a283bbc1c45e3e94fa1476612a0b14357b5596ad38e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:1a6c64f38d5e9fd7c8cdaee25f8f5871a35a6f58d15ca6f069810a32baec5176
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:3bef3818771932546deb73b20e2810c0ff3b6f8c72fdd6bf52af4309e535e0d9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:78374501b90de04aee09da792a2de16bb349b8c5248a667db810e675ebb594ab
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:d94664e7cd5a10d86f273aca160070305080012e66551af59342548d5d68f154
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:75c702e981bec6207c8b7044144f233e1b9f3aebf6673b041bd1941abfcb6c76
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:85ba37ddc7d37c8dd2b2f1859713f19789968e957aa062da85592cceb09e0131
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:840fe8b35a4a9f8ed4575c37e95e769e367525d9415b0a0463848b450fac5116
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:efe11fe29274f92772613f7f1d34b04d2a1a10c46f2344a473006af7c5c4256e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:eee970634f7657e11f2402382ced6ca44273b5cfdc6c85ed9553982b6614d8b2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:74ec1f4475b7ed8c4ba175872b2360e09d2da59adeb40ce98a2c9fea2dacf96c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:3a2e1a0433b44c54c113e584b2aaf68de6b5cbf4008676757dd503e07e3d8156
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:393e11428d7848969e9963be66a088c685a4b52ad8ff15e11ee365b70f886b55
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:c728f3d1a10e490f0c6b092276cfe695ae79ada7c06b6165b172199a2b819637