Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips-dev, 14-debian13-fips-dev, 14-fips-dev, 14.24-debian-fips-dev, 14.24-debian13-fips-dev, 14.24-fips-dev

Index digest:

sha256:73c4ac7b9acb63986858e35734e77b84b7cf3e15b5ea678d61e7ba4e1130fc64

Manifest digest:

sha256:adfbb9e35094226b04c2f3fdc3c841a083eea10b9345bcd636009afc11e68be3

Size

130.32 MB

Last pushed

7 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:fb6fc19eec85fee360c7c1afb0c7ead84cf722992d99f088a66694929542a85d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:136be14e6c6cae13ee4ddaeedb21b1a13742ce92feb1befff2b0caf2326105bc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:397d32d760b8a95e0a21a658fb2cc22fb54567c07aafabafeff9823edeac192a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:ecad20af5e0962f2c2cfdfbef9d272374c20650321c1b403d157b727e4202d1b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:215f15d9a232e12f947329012d4096a15415136ace30168936830512f2abaa75
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:391418f399548b6c9ff6fad6756329aa6d226b54d34ccb23b4b255ad7fe56d2b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:b1c10c68df2251bb83c43c5160b431b8ce13eff4989844ad1a2bc65be897f388
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:75316b06ec0771eb9bdba569d4a0384b927505ac87e633986f9eb8d821a384bb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:2f39cd21f4b4a2ff5442258ef3fd26c01f437602479554bd9accfac02c4db05c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:5f8dd6f993cbdb2dcdc9df9e7b9c91a221db9538c1aa9108851bc38b4b396ba3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:d22b8fb43bcdf6c379b8b4a9ffcb16ba68d0d377e83822fe2664f15541aa887c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:f02b66d9d5a6d92c8bdd6387c1f85e0123e9e0f0b3183cdb26c50412bbd870f7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:5fe6434808ef11da96088d90823c7b1677199150cb92e0802dd677d8f3c8866d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:5fa641bf2a7c0a40a0c344f347f41daba535248c815a196a8452559917af6f58
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:777cd2c76a9beaef1dc1bd43197c95bf8e88b6351373d0f216260704fc2cb0d7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:8d78971509fcfb88b1c9ed810f923d4aef153131d7b820aceee0bb005fa0a9d2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:4a9dfe993b466b4cebff9ff703f9ebfef418c552636276df4e9555e95b282d71