Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips-dev, 14-debian13-fips-dev, 14-fips-dev, 14.24-debian-fips-dev, 14.24-debian13-fips-dev, 14.24-fips-dev

Index digest:

sha256:1989ba263fabcc1aa2e4bc668d9b73960d25c97620432673dfb60da3b1d84e91

Manifest digest:

sha256:f83620a347465d6351d0b545f8b1e4ea282b477a79d7dd73727f0bf183f7b0f9

Size

130.32 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:e384dbcd645f4bb42540baa81da24ebcec06c8befc26b383afc1dc32fc7f0666
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:7f5a8501fc0d486be7f43ff68fa0e7e954a4bb8b7aa744e5a36c4e85bfcb8751
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:6acdac2d371d089695f9b08bf75c919956d9675e4745f33ebaff715e3595a22a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:8f2831a2a281d57ff07e12269ac9d6c6ed7d91e3d8401abcc06c647a5383e784
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:42a8abf1747925a452d21c11b6015976fa0ec7e312c3b9093e65e6aeff48daed
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:2dbf8a29ba7e2826ac08d1c735827f43ed41d83de90e7343e171f960059286c6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:40cd6f04aba4a747dabc9dc14202874c2e17fea348c1a3a2240d29dec8a130d7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:c60a88aaae33536ce7125e92c1658176c0cb1255499b375cd43a35a0a4256460
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:7cb46b4a06a4b108332d5185a00939cf50f95d46a1b3cb0acae7cfb98ee5653b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:6e871c5718a7524fe96f9387645a462ac97e20caf8680b9632cf407c61dad2c3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:e26048dc6186afd66447babef6494adb704a466c44441da6663242574c14bb80
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:3e587862f0ed0065ed2f10fc0b88db4f8ef567e2d11ea8557e9e614077576ff1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:eb644e2f7503951a8f536861eae0150194c7791a206a4a8facd3928a43bf0872
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:8b30ca7865a5e437ebf4ffa122fd3f5a9574e306afbb642d7b13e24784e3f5de
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:dc89ecf4fec5e28d3b7d3f9283eaa20b9bdac5fb35b693670adc5c4a064a3a52
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:8dd1fcad82bc6fc6bd9674d513cf887f0fea6eb43888e0733d6e4bf3fe6e0bdd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:77999cdae44afad2210d2cc709d2c2fa8ce736f5ac813b0ce32c6475e3a39d8b