Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips-dev, 14-debian13-fips-dev, 14-fips-dev, 14.24-debian-fips-dev, 14.24-debian13-fips-dev, 14.24-fips-dev

Index digest:

sha256:5ccd1467448de9115238d4b324ac971ec7c8f89325e5b17deabf71ac03c48232

Manifest digest:

sha256:a6c52236cb5ea57cb9fe8aeeddb38adf32ed2b7e7cf3fc7839781ece828e78c4

Size

130.32 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:723e9f010c2d6f417ed3feaf83fc0560412db956e4619f34e64820e8f7f1ba8c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:26319a288dbe6f513f43276d7af3e38cf14937bb356a4a38f5484fd5d04641e2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:e4baaff4a9b25abea886029a8935fa4621ceb0488a5097061ac1376253453f95
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:0f9551d0254cb55b6b7fd5ec3ba504e96fb63b13a63ea35b0f7b36f8dd0c6739
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:507ced6b6ac736c676f0ade89c18c7bd573763b6d4adce9ff908e28d18ef6387
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:ed580aed425b9d05b031e4dddc03b1bfaac0f643b5e56584d6d7d3c17742cb0e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:f806f7afc88a83d4fa397bcd3456b66b164e9aa5c79a6fb14db24e703beb3745
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:9ce5c3ee14524a503fedd04c2d35d9d6576e164d0bc270e1eb7f6f01ad084b58
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:c8fed6641e313c60d22044ab276921fcc5858cbc10184537432811e2a56c0993
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:61571b62c919998a422a77d22922b89c0f247a3a73fe4b632e6797e73167dbb5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:8b8ac248784f851655e690fbdd67d371244f1a47a082e94a2bfb769f1b34958d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:5a6c62bd5c5059bb3114d949002cf53c8e5fc5e788128c56b3ca3fea93d6a28c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:31e0caa052fce894651bb05cabfacdf22478203154b552e60952bb947961dc74
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:f6d5384e8d3e1025eb2f53beaff474c3977afdf63f1eec46e45f44cab24451da
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:71eb2b1512fb822d4623a336af9d1e844b6466e40a1690da4ee0e6e8411879b1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:87c582612061008e84a02b5c4e5add41422c95c478f0940e637b9426060aed8a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:cd9b31bd95027d769fc620d392fe3ad33aff1e5160cced0a790c58b700e0b8de