Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

14-alpine-dev, 14-alpine3.24-dev, 14.17-alpine-dev, 14.17-alpine3.24-dev

Index digest:

sha256:2bc81bbe381d5c506ba93ce791ffabad0d61cf67d57401137846baee1f822726

Manifest digest:

sha256:9339f74181df8f111adcbdc824ff7f5cd3480e9f7c9f655b7a6634cf4c11cde7

Size

133.11 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:d9232bc44408eb6798af62b78c3c2856067153a9686bdaf25fc07becba33a781
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:40dfdb9c21d00c9098bee5aa4c907ca5afeae6fdfb815a7e55aa68879ed09bcc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:6207844d37c85e11fb700744ceec6971b7cf7801280259e9e9aea866a0ac160c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:f08f812bae7e4b7e90372e17b52c00adbe23668474e3448dcf8aed0d5601241e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:037cd5f12b6ced2f449650e9af92d7cdffbd50462cdbf06e2d99f138419f93f3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:dc35e48e9dda4e0b6918b470c5db17a1b806b1c95cd95c2ec1f560e464aac25c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:26fae0ebdb2045bdd3ea3c46cf51ccf0c59a42c6bb0b85311301d224c04bbb6f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:82c7974871f56436a2e321aab11d105244bf2165b6e2549a6bc09289d2a210cb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:de046dcbae7dac9dfec065ea8d9a8a78d0533959b3749e04d21336a197b69022
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:3db0804a8c8f00079ef304e79aca3c0ef960b941510c0e2280eba408a2064600
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:c75bc4c190c4312dc188fa02c7536842380fdd9255682b854013ac76b1663445
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:3cfe6dc7572edc84dda0b649d75bbf6d989c2d1133f1f68e61915f40c7da63e2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:177e1a4f72c5c972e63b130d30039e0705bab78d009eed699cb63fa9825974f9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:92f5db27a4a2a1ccbf826a7bd82977a539acef4a0a8b5a3b66b94011ab14fd38