Hello maintainers,
We are evaluating the following public Supabase Postgres image for a controlled technical pilot:
public.ecr.aws/supabase/postgres@sha256:42088c86593e0d4f47b2b2bd3c964cee31a1bbc8e560619fd3e84e5fdd973f6d
The OCI index references these architecture-specific image manifests:
- amd64:
sha256:a89d080bddb7a99104a01db136702c16dc5748752d2a9df57c315703346cc684
- arm64:
sha256:85ee233d90b52b3c012e3de2214fa7b4e8cc4048fd18c5f99618cecc0eec6898
Could you please provide the public location of, or access instructions for:
- A signed provenance/attestation bundle bound to the exact index or architecture-specific image manifests.
- The corresponding SBOM, also bound to the relevant digest(s).
- Public verification material and the expected producer/signer identity.
- Any applicable trust-policy, key/certificate lifecycle, or revocation documentation needed to verify the evidence correctly.
We found the OCI-attached in-toto/SLSA statement payloads, but they did not include a signed envelope, certificate, or verification bundle. Authenticated queries to the GitHub repository- and organization-level artifact-attestation endpoints returned 404 for the three digests above. We are not treating those responses as proof that attestations do not exist.
If these artifacts live elsewhere or require a specific public permission/API route, please let us know.
We are not requesting secrets, private keys, account credentials, or access to private infrastructure.
Thank you.
Hello maintainers,
We are evaluating the following public Supabase Postgres image for a controlled technical pilot:
public.ecr.aws/supabase/postgres@sha256:42088c86593e0d4f47b2b2bd3c964cee31a1bbc8e560619fd3e84e5fdd973f6dThe OCI index references these architecture-specific image manifests:
sha256:a89d080bddb7a99104a01db136702c16dc5748752d2a9df57c315703346cc684sha256:85ee233d90b52b3c012e3de2214fa7b4e8cc4048fd18c5f99618cecc0eec6898Could you please provide the public location of, or access instructions for:
We found the OCI-attached in-toto/SLSA statement payloads, but they did not include a signed envelope, certificate, or verification bundle. Authenticated queries to the GitHub repository- and organization-level artifact-attestation endpoints returned 404 for the three digests above. We are not treating those responses as proof that attestations do not exist.
If these artifacts live elsewhere or require a specific public permission/API route, please let us know.
We are not requesting secrets, private keys, account credentials, or access to private infrastructure.
Thank you.