Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips-dev, 14-debian13-fips-dev, 14-fips-dev, 14.24-debian-fips-dev, 14.24-debian13-fips-dev, 14.24-fips-dev

Index digest:

sha256:b37b65333a88e0eb5915234e16f4530077481e02a135dc3b04fb1b3f01b1e707

Manifest digest:

sha256:7f4c149d70c485d9978358c6c55093de00fa1651f971f7451e51bfd21989113e

Size

139.60 MB

Last pushed

1 hour ago

Vulnerabilities

1
1
0
3
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:c0f80391c03ddc1e017e93a0f7eadaeadebd21b72f53f56fe8eb987bffd40bd2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:da8216422f71aedfa6cd4004edd09ac923e59983a0f528c468221d9bf6399238
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:acc5fecf1e022d9062f7b2c98c00e5db5596216f52283114a1c853fa43cc13d9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:8e03c952c016aee92f5f86f682cce6eaf5a5206bc00975f310caf4b2fefe4274
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:fca049d4af285f3e26261cf06f030be11bf5c10ef5c90c53f8c72fd0539af38f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:b1ffabefdce695f4ac4090873153e770d063c1e0e4579a43161ec970dff3978d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/postgres@sha256:9b2309cf509cd057c98cbb3dcca92ca8d24f173d718f142f6ac15520827bb58c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:03d437400481d56fa7d8f560c5163e26acf2d013c7982c0ccac376a793c0522d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:20ecb3af0fa04a01d1ffa44b1fee79dad723f855704342d80e0c3b399127d1ed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:e4b42293c40451f9200919d17847d566df52422a81bf2a2815eb9931c9958757
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:fa12bd6a8739c00fd1ff963dc626ef543b9cffa538cb613af7c3958c927c6420
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:4582850d53e45492b8c5eb2756d0dd0574a51956c079a3d1285e0d01a0cb7991
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:19f7bfc9573f1ec707dcff9e32402d8a5fb781895d74cf4edc78caf581a233d1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:d786bee26fa468492b2e9a5bad1c289e21ca32df34584dbfbf495369841c42fb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:f18538eda4b556a9af98ae66b534bcb65f564047be87df6695620e275a33c914
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:fcdf67ffdded3b9170375aefe897731299b134be72876482696fbea8a7cf3fda
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:cf6a344a56f49587fc06d4162870e2f15b56c886168bc23bfd898a754d4d4bf3