Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips-dev, 14-debian13-fips-dev, 14-fips-dev, 14.24-debian-fips-dev, 14.24-debian13-fips-dev, 14.24-fips-dev

Index digest:

sha256:cb13bc88693903fab63dd8d1e2f929f24f49fed3392a0023d417d5df4f99e8f9

Manifest digest:

sha256:3a1dd74322a091d79f4dbcb08b52bec46d7182119fad65ebcaeeca0264a7b254

Size

139.76 MB

Last pushed

3 days ago

Vulnerabilities

1
1
1
2
1

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:86415fa2dbf2c4f57aed90755488322b8a5b49daf2f8c79f5b203ddaa8095094
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:97b84c05cab8afaeabde2b535c7dd569cf8cde9673436a2c4bbd2a15d6675ccd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:e769f6bc75c8fb29908c0b7faf001885c01e1fff63c68c6d0557a60d3f891f37
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:f50815e4e2bf5a8165623e9a8ce030dfe1247bbbe5bcb6b5797d4619e06a73a5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:f32d20e85d7b4177fc5d6bf640088373b22a3be0aac674055b62160cfba25680
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:1444f8ecdb42196003331eef757a8c9c56d293fafe976db0c4a05d850a31ec51
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:e5e80e0e63a5bbb51065688f9537fa261fa807e17730b5ebd72f52d0f633d6eb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:ec51b478932a3aae4b6969784073fdac6be72fec2b6010f3d534e29c0a941a39
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:c5dd17f612fcc776f1e11ede06437f16f76afc206522b13893e1cff98051086a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:e3299622375dd2920f66cd52d2c27c3a69a2426079389e42a6e2f6d4eb38dd2a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:dd487cb2e589a16e668153b18e0e4c7b62900bbb50a73e2f687b7c1edcad3fa8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:1781775c0b7cdbe88ca7d6602b6f93d3ccf2107c94484ce7840fe4f9924644cf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:3ba4e94a545770a399769e1afbea4e2a31e02d67e6c97bf8bf64594df642739e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:f687cefeef3212953a2c08f583f8b2692e55ab880a51685df5f9e00cbdce36e5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:4b4df41bdc59d8cf9fd06530838aff14ac9bdec2a7675964553962380cecc301
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:a6f9c190a725924b8c8de551f2857b622e9b62241c0e789e17a27d31a4a738ca
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:13b805f5e98ee01c9bae31b9892e2b1cf91e532ff7948326b919268fb2fa0b37