Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

14-alpine3.23-fips-dev, 14.17-alpine3.23-fips-dev

Index digest:

sha256:ce00913dc609d33f9773fa80d8a647c1584e28080d16f6ea821b6b7cd7c0ba73

Manifest digest:

sha256:a1944de78f2c88777f9acdd4d232c82e5bbe647cb7c18c51641566fff1f4ecb4

Size

133.93 MB

Last pushed

2 days ago

Vulnerabilities

0
1
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:b220599663c49d8ad764d81f8a58b05cef59d09082a6390844959841a5b4ce7b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:d817c20846e10fa98750e170628c7475b107133692ec9bdac6d225e84307397a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:ed2e548f0a97906eafdb59810a7b11eb4a92bf74fe8ad2098a22a3da7402b8d9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:ae002fffcdf59cdbce47cb6cf412e917dda24bfef467b96d3379dc7b075d6bfc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:b8489e15fb9e9c6a733670307ac5bbb7041d76bcf6749d805ba9a1c68812cb93
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:1d21c1e34862529b5b803eb564b155696ca0fb1edc6476e4efbcdcda191d6795
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:706231b2a853abcc38fc2ba2528ace0e566e7cac54c54c0cfa8f4342fef30baf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:05d36e39737c8fcafac9f6ac05ab1a75d2858b3236d6416e13ee02db393dc07b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:e442ec6230da779f48f957a0c242f87136784d82bda10e6e359d29ac98f48fbe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:e2a9e6df0bc107c54724ea3a1f40813703faac023fb6902f7d318e22f695beb1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:afe5b81af1c4b06f9d33bbc2072c679039ea643b32e2c5ee8f7c6b69f50567cb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:4b46793b5b8f2a72ad2a6697e6f93cf1b8009ffce45436761f6111c8387fa890
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:ff0d6efb9703a0ba1653deacb38d6653232c72c3f34c204f8eeff25beb91a7db
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:f39e285eb3b8b4caf1c7feb4e241b87019d46833d8d6e7ab9a031b1ede3c5305
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:de2946de3583ea84368627321c0388f7f098efe15a8d53d985bce63af31d9f52
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:2f704ae6328add56f10cc514855534ca66c425190153507be39e58ece6b87934