Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

14-alpine-fips-dev, 14-alpine3.24-fips-dev, 14.17-alpine-fips-dev, 14.17-alpine3.24-fips-dev

Index digest:

sha256:4a67143e343944ec7cf4d10c62d96db1c4a922cb7fb5e054db44cd3b9b18c9b1

Manifest digest:

sha256:4ba6ae212f35649f408d38ba4e083767af47c258ac87003d858c37209b89d71f

Size

134.28 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:5a1494601014428a7f7943861c8188bc320ae429b6830c5cfecd5a813a3493d4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:ed242f46c5b274c68f3977a60f1bcd0956acf35feb6bc088718d05f49c271d30
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:15f61f0e514f1bc4e665db0fca5cc3ec441c5e8180f36b227904cd2e66cbb0d4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:796d36e8c8e804bcb85733cb827791025b782d47019223ab05604d6b846d7862
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:da39f5aa47a1b0e5e6caa326a5874311c42fc549056b062a7eadbe83187ab371
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:37686ea57d3598697ea7de4618334033771916c587e7efe3db4162a5bf025fcc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:e5c6cc8e89b9e3a71eb94b8abc4f2523f0a7f9f20e6f8e281bcdd39d4a66e204
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:469d633e16ef18640413a6a71705b9a99b123cd6eb5aca9f55220340471cdc9a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:6b8470166226d6ac41bc74642683abd4d36263367c13e7d8efabf20b824ab5b0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:8ab6f1f694dcd52ea01217f149d61a6e7501f243244543c999edb0f1424f01ad
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:cc612b813e2841358736e82d44ed50a640bb3b39cb044bc2d8221393a7666c7a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:b43c82ab615c59ebc9745a940428ed1d2b4d8146ee479f5ace3552cc977f4f2c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:93a6d16d2a6082237cea81627ced868c1c1cbbd8a67d04177a9d511f502282de
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:4a77dc287fef134448839ab474fe2e0767b98998e04078d61ac0365aeb87452d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:3b2e41f9a28b8e02597c152a1832cd9e5b290686593e58f3831fb2b4494c8549
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:cf53d229bcd13f984b2eed68300bcec5f56f69e547dfc52f69843ed4dfb98c63