Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips-dev, 14-debian13-fips-dev, 14-fips-dev, 14.24-debian-fips-dev, 14.24-debian13-fips-dev, 14.24-fips-dev

Index digest:

sha256:aa7c41ab65a8e1faa83773889cf6141b6b2e2efc0bbb7211390e915fae4d7e6b

Manifest digest:

sha256:e22e9c67013e1fd65fa194f0d1f04056fb9d6a5c07407a9753606bc9cb2cdc9b

Size

130.32 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:9b9ac992c7670f71300dce0e7ec75f2a162bc2021b6ba4c2cb44459a143078c2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:e5166c753e6f04f055dddcbe9ea03d881c68c810c7cf6149912c693c3762aebe
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:074ccf158c3b0a5d8459d865169cca5ee2f88d4f0ac297cb404fb6112dc5a7be
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:7ff73facaa13dfa480a1e75a36ed69ac168408203b0576ee91bb3280b0ea6642
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:ae22926c3685bedde25472c02840c9b13749b5b0b4b53189d69bcd5a99f03a16
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:4a4a7ef084491e25a1de2417e14492ec8f532d8821ce2796804918d9ceef9936
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:caff59aebba75ba812406d9f05fd6383e793537dae0660922d7c59edd6fcead2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:0abed8423610f92cdf7761a3f7ea8768469e2f29af51f2d85e091257c971b94e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:583de91bca7791763c24c33d88fcb2640488572c443fece9cae5b919c6bf926a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:fbb7d48d28f5baefd20933650a839485d124637271a6e71963a9b4c4ceef6011
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:b88bd15eb569a28b365e50d9862ee1f5f800dd2d628857c314157c185e74a83b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:336ec38c6389f963a42ab2b3ea5041127ba4d99629a9ef51ca6aa38cf23692e0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:904cf79c576a5159716c18d31198b3d1935f53b52e391be7fd32a930e58c7a5f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:036081d216cfa345468ae094b3c1661edf123b4f09409acc3b31c43683fcdcb0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:9fd486f9fd4650b9663ea0d7825c30d8edd3e9a472df364afa4ba9f222e5c557
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:69cd668ec4916efb9c024340b09276f210a4950a87b95b0f51f6d17596d4ce21
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:665913b576e3b17029699283e7952f4e19453bd56b5ff10175aaff4611c4559f