Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips-dev, 14-debian13-fips-dev, 14-fips-dev, 14.24-debian-fips-dev, 14.24-debian13-fips-dev, 14.24-fips-dev

Index digest:

sha256:716dd5c5eda4c8e57381a912e596667ec43ffdf47108f851fe0fa0c4b42dda60

Manifest digest:

sha256:42d780d18864ccdf90f20095a45c4a0aea13035f61a64c27d41584e4e4901545

Size

130.32 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:3c091506c88b261a71491aaaaff3ffb48b93ed28a22345063d032e31339bc1d4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:b0ffd81f1d73fec7910dba7de6130d4d0da2ff42b8489efb5cd2ce0c4da719a4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:0ac72bec86a7a0d21b2ec80d880b0ab6d5e8e94a00e1f5ebe845037196facc91
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:c9745ab5f35a5a07d3f9e2811b368b48085cbe10e5564e0761fa57ce6b98709b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:82d804b11ccd0ca31918a611eddf8cfa682f16cfbef6101ef3d738896a4b7c95
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:841b2b30399cd2942bcf6ea987b488b11e701bc6fa3fd035ad6850bee379fd2e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:e58fe7eb8dc21558d50268e242deddcef3dcdfb17884860441177fd63b680ea6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:882836374bd99742b5d7bddcdc5e1e6e739486809a6d20e659b350c08513941f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:a09fa198b93e507304647e5776b72a196a72e1cb7282299ca60445732ffb8849
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:218e374a1609380a0114c807fd829e5d8c839a5a8f30679d9e0eedf75c2de44b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:37f332557dbc96d38bb9972e0e34c7ebd71edbd4666cb67d97213538340da63e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:80946c376fba299cd3ef2257819835f63a713f8b03564a01cc01b75e6b6609b8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:6c3a1a594ba031c816aeec5850e6f9a8c3a64fd3ca93feb96cc8089fbbb916dd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:090131cc5768b731ab4f299abc1e553efac595f8229a5f7e4d37e2b8936414d1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:d6aefc982d7e1075d3a3319bfb216750431b437ce21b942e20bdf25e06921c46
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:00061c75998f4a927bac7b5610705adcf69b23398ec42bc781330dd5b6e1c641
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:5927d4bc022c6e98edc48eb56e0dfacf30127d6e9ebc1991475bec68511a2706