Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

14-alpine-fips-dev, 14-alpine3.24-fips-dev, 14.17-alpine-fips-dev, 14.17-alpine3.24-fips-dev

Index digest:

sha256:af025563424dec499a39ea84e612b5e2e07d94f09be369d5a55a358bf209096a

Manifest digest:

sha256:4590878b9f706ccb18aaee3bc5958b0111165ca38d9da3cc437cb6ca52690736

Size

134.28 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:6033e37677c47e67ef0c5bf75650207067c74b529d9e6869b93e50fc5ef16e33
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:9f4788d9f9e7873e8ca2c4574f58d6aaac7492b2c1797d7c88cd0a1c78cb2894
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:1ec0640af50bda49eb53176665bfef5fbf83a04c0816ba588ede6446dc04e9c3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:e7f198168f0b27b6a745eaf4b12ef78e18368ba6ff0994241a949d67d08b6859
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:38fafd90d478a93225ba3997387446bc3ceb2aef0c95973d5b24732ac6c79a18
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:3481ef7d8f66c3ca8ebd5fb785b2a50888b4eb1bc1deaf470df3da31d799cf24
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:4cdf20398aa01cb292e82c3ef3eef6b99e24b80d254ace6a89ecb6f9bbae83d8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:6115f666941d77c8d65d42d5bf27e1c57c2c75f5d4542f349625b80b946139c4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:b4e3a30c0f4855f59944f184480e8d94b35340aeb34a04949bde6aa5422ca592
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:1c6df3e05158284e65be24dc08fc85999d7c0faad276e3180552bd0301961e51
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:ff10cafdf09aed50775a4af5df0b17a152057a2f7569b84d9446a8c93bdf4df9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:7701ea5b037ff9e69d83421db7e6ccefe3c8382240eceef22ff4a9ba51bd8ccd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:9adca016914c359d4db40308941d93f2065b5a2401e99e830ceb807d8fa96ef0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:5ccf458cfd5a31641a6ed1f40b4989abe73806366254e26dd58105c9909d3544
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:450f03e969efe33cd484c856b6aeee9c47f0781c414415ae060bd515322c4053
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:efe726939669730638eceaed98f9e457c26d809246c5bbb6435716cca2feab28