Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips-dev, 14-debian13-fips-dev, 14-fips-dev, 14.24-debian-fips-dev, 14.24-debian13-fips-dev, 14.24-fips-dev

Index digest:

sha256:b1d43cc990439861541bf13ae0c3842cb29d8de7c397e0829a098180e0190387

Manifest digest:

sha256:790e4e227e051adbbc79d0ac88b8b7bed530ac68a248752cbd8adaa3d832b9cb

Size

130.32 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:4d72e0d172a3c7ad1e49830bfb035cc14bf8de7816b4c36f121c5aa475008b52
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:8d1a19b4875a5ddf29c39406720b55b3c93bc6581c5e11b51e4037e645dff16d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:18c2dd776d59009e3fcdf1967d7f1c67dcaa9fc9e7b7a48c36a100c37a3bd469
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:c3793010378299360d0dac0d510a1d4c913073f4ed202b2659f0c6e48be6bf01
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:2ac1340096f5201405a2330035be4d11435244597a85ab22aab9991693e3ce67
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:ce8f43423d883bdff64a85b7df0a971ba477e630d961e5d405cacd5fa9ecaffb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:efa552524124b56ad14442577570567e670b493134b7fb0d245f3164335d7d10
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:03a303b984e7cadcf0c68b49d3b05e976ea07b18e1292e3239a27989629e4f85
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:a295f0915d2d11d836372096905116e4fc651e266b988def345a915872b2d5fd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:ec5062e1b33664277cac50c1d7e06425949bb0e74719e4a80b399113ea77a7a1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:c79b4a64bd2972515acca683703a8b84d4279a7fb5cfdd12199470b0b9a299c6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:d85d59bd0baca1d6bc7dea6d4d6cb6238515ac776bbc33dea17b3673a473032f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:10511ed41beb1104dccd8e1e49a70eb2607e36d90525f22db9cdeea26ac9a91c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:ba06903a8aacbf935ddc69a90ea4b5402658660ed0a0218e644b60d3cea89cf5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:af7b502d0d868a0b296b49eb1e4cc8060c2d2dd531331395c7385c3b53c0dc0c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:0b1d82112cd35d65b4a53dfdabec69fb662340160656d76360eeb915812ef0bc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:a46ac5a6b96863920c2439a691afeb3009c4b93acdba992fee2deef06be03e89