Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

14-alpine-fips-dev, 14-alpine3.24-fips-dev, 14.17-alpine-fips-dev, 14.17-alpine3.24-fips-dev

Index digest:

sha256:9af4d6d764385a8125be1fe0e11a4058d18f7c4facf850475e1bb62c528ee946

Manifest digest:

sha256:0e3a2bf81ed1371fe71e74a634b8b6eac21da39fafbeb41e92d718367e698323

Size

134.28 MB

Last pushed

2 days ago

Vulnerabilities

0
1
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:6915d1d7d2524ad405be3d12c1c6f26daaa4eb35b8e7badb4f86cd89102d7814
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:3457e046199b055dfcb4b35a5411de37de22c92c81a4cc0872f28d65e420b767
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:4c1eb717a5a62f7427a4a9643ccb9711db3b17ed2651a556027d73ba5d58775f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:62c6b61f625f309ba225da12f1efabadc4dd2cc01b9351c0a8b1f302660d9522
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:ada2a213a317669a9eaa24253c66143b70c1f8afae3e708f34f17ee958e43559
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:8c1d236db3618757b84d3fed77f20ea0b2438e8692ac25c0125c8e9ba9fcf275
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:5cd72314fbb6571d3e31017dfd9eb880441defc27395c09c9b1408aad0c4ccd9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:c41daaffc506c6577f3bc2def22d077f8f1306a382d816a7c81539e408ecb24f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:3826c2aa40afeed386bc78cd17786f875c09ccba36cf9bc6b879e7ec648a7c77
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:a46d4720f8a5f8ecc50062d72a9f03f30c3eb3e3fb2d86544c819bd72c3db9a8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:85793eb7fe963e7e728303a296e57923fab62047ab66c84c11cc9518de0f4f4f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:e7172064edcbf4933f0656b299a3b4c712043366ff7b0d493ca481fa12185e1d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:fbb8c005741d01eed8cc5db8afb056fadade47777d56a2b07dcd14a87ee034c0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:869269fb46daa00bf117379171b0ca34cd81bedb7fa00624b27433fe7e5e63c8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:4a15b8b1dfc8912faf1597c0244ac2076d714da8f65d28781787c71353d0447b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:7a3403af52f7277a1afb0821c5194ca7f3c40acf0c5ed4a8567d2bb4575fd26f