Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips-dev, 14-debian13-fips-dev, 14-fips-dev, 14.24-debian-fips-dev, 14.24-debian13-fips-dev, 14.24-fips-dev

Index digest:

sha256:87b3f0b378266e6e30a2bd3d8cd3e3867aa549a18be5a5488b88ed0cbc57314b

Manifest digest:

sha256:48f4328e641d911e5a9c22dbbfb65dcf5a084eef6949fc59dfe553ed3f8dd884

Size

130.32 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:e0499c3e74c13b0ab4692e86bdeef48592d5f9b1e7d6bb08113e2ca24980b787
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:d049cd773ab3ff9976a156a4d31c5c44b10f5f955796645fe743421501e84151
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:b469d09fec228ee580e9535f99513db5f9d6c5d1b61724226925597a7d03e458
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:43c1dfcbaf1830b9ce761b210da0bab8f764324b6fe56cfd26320c4e3de3d81d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:05c8603c12270bd322c8a43b8abc9254f9e491cd806390d2fa0816d8b710d603
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:d2c0b2b27787b44902f7e5c1eae748cc97024574e8128ee9c323003ce6e00732
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:7fb682b0f9576125f74171ff5247cb54fa4ceb8f26da20017b7b4270c698263e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:6ec15f010af507543eb38aa1a2b23c495c22d27a7a686da5594a44483c0fde06
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:f88d60915dcf8cfe18d2044d280a52eb735533531493200ba49d188f2ea8495b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:4da16a39dca55151445b460833699d119a1071a67e939f6f937f0d785e73ced6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:806e6fda78bc167f224a67e65561fcb0e541eb1c0e16ec11852b3295534fee69
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:29c0a4dc959ed8ab583ebe455da5bd510bd2b9ccfea471bbba14b0d0455925d3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:6ccc34dffac8b04fda2cc4ed17e5c2a8e4dd119995877f4ba61e0d6bf880deda
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:0e5a29eeb09ad481bef564adc676725ef9bf45be5a2563447f842fa5f403f430
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:1e42cee644127b9f3d8931e170cfe50251298dfd44fdd0517a6cd324561a5429
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:d97d6c146ca13bc18d28f9badf602da04209dcdf5ad8d57958c0d90c8cf8bb45
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:4e43dc990ecd1992991c95f0ee78d282d57d27a3187214deae164c73d65e4ce4