Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

14-alpine-fips-dev, 14-alpine3.24-fips-dev, 14.17-alpine-fips-dev, 14.17-alpine3.24-fips-dev

Index digest:

sha256:df113ae751f057a764446527c4cdb83b1e1e9b3aaeddc7df394b03928a566f6c

Manifest digest:

sha256:32811916cb61be2f64fac97f5ed9766afa439fe80a9fcc3044c95a6f0fae3983

Size

134.27 MB

Last pushed

16 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:2f33b61489cf643578581a50e8c9f49db39747f2f1822e5e31fec31c39b4025d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:0e06f87cee7abdf02e30310f72d68dd7926172d8e56d3cab4c95ef931316d3f1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:8d19274a04df5866ceed0b01960404d8d2e975c1b78217db19c54feef5ab2438
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:9a9138a4e7358b864baf3e9f838ed0b513654a5903e588753c322c6e4578df8e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:02f46fa038f7578bf43d2adfe58e04a530590ba50ee6579e7f12e5ae18e5e885
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:7b5e921850163df412b0505bfb4fe0a33a9cb55d35f782202c4d916e0bdc4e84
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:3030fc0d6d6998113bdfd8cd0ae959d7fbfe913e5b2b21b413084f5ca57ea078
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:9256b076db8688474c27e82de1a67439311f0c0f9d07280260f1d513e2491b12
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:44d1211dcb251fe040171d7b00d971975e34080a1e94de5336bcba5f65aa9b7e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:04d2635b9bf27daaaa1397956b1f2f9099ca000328a748b0e0eb71b59cec8dd1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:02e37d0f3a2f951ee39671c8f902c61cd750a58ff52fb7c73e6c7226ffc0a027
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:919ceb887186fcc48e671b91cf15eb312b6d826b3bf8ec0dc195f02990012f50
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:acb3a0faf6fdb1a63d5d7d28b12afbb8d4b4207a6133a0ccb2520ce56bb272f6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:69331e30e48924628924a639d8bee86455a7d9b770ee0edae6daf66101ca90d1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:52e2a3d2d932ca0a119567b0d9da5e773998675dede5bc374638b44998f92460
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:5eddab7780159fd65f77386e6bf051e5c07e8a7809a86a38ea2c1af5935af638
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:05e8e1385a54e23d12aa7df15e8e1e561cfb621b9d82c9e19fed8868d607191a