Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips-dev, 14-debian13-fips-dev, 14-fips-dev, 14.24-debian-fips-dev, 14.24-debian13-fips-dev, 14.24-fips-dev

Index digest:

sha256:7f6d63a4044cc07a440d0d46f067942d5171cf675cc0741eaba705e9b53c04c6

Manifest digest:

sha256:a854b9c9891b1d52b2e0c780bc2669c2054798d9f7895d1b3afdf0346c7c24dc

Size

130.32 MB

Last pushed

4 days ago

Vulnerabilities

0
1
2
10
1

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:0a3efcc3a498bb1ee5a1f3abd5bb0ab00a2654f7ac86a56dd094666985acb98a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:d2af4666fec22253e2391eabef30bad9281601f94a41982b45deec8ffd98d706
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:bab77f3dfa85bfe532a63fe2667899986944cdddaa823145eed9d735d32d669f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:6ae4827dea9f22e65f7b20feee02cd46a73429b4ae8034ab866d9b64cdccac9c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:f84ebd66d99e83d9373dde2e1428477d4f790aaaea8a3d9781b6942d1c243af3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:8574ac3a1aa8d6e69199fabca8c3cac4b41c4df69058080be16c2602fadbfb92
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:1445ea619fb5716edb75fa8427d41bab489151edc85f59252809a47e528d8cb9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:a4aa41d91ad6e90ec40b5e54dec7eeb380a6f920b4f4811037dd84880625baa7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:7930dd7740f80fb661d2c7722b2a6868ce062dfeec21626cda56758db2682528
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:c27e18ec09fdd6f0114511dbefffd0e87612064361d8aaaf4de4711f983e4fd5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:c4502a42124e722cfdc7bf05c7a7d4c075cf1e85ff420bc73a5ba27b0bf59a2d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:3ee9a2b96bdbe97a0a7cfcb2ad1aac17813dfe121f3d80e66c65a2b3993b83f9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:7f2d30c82e7f9e8241ac459e8de8aa414f3f6177596ac8f6fe5827699b1a099d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:fc2a807ddb71cdb924e46e621eac9e6330d1727a0315ec16ed294b4c2d850c2f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:ced54a09005e425518e186c3c2203d5fea49a89d7016abe516a056a0c41229eb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:e38389c0fd4795aef97804616221b128164f18348a83ee3bc4d738639c2eed47
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:06113283028c3c29830a096196782e23dd835e3a4697e2646b3ac12824a18d0b