Skip to content

[Supply chain] Request signed provenance bundle and SBOM for Postgres image digest #2440

Description

@Alamrob

Hello maintainers,

We are evaluating the following public Supabase Postgres image for a controlled technical pilot:

public.ecr.aws/supabase/postgres@sha256:42088c86593e0d4f47b2b2bd3c964cee31a1bbc8e560619fd3e84e5fdd973f6d

The OCI index references these architecture-specific image manifests:

  • amd64: sha256:a89d080bddb7a99104a01db136702c16dc5748752d2a9df57c315703346cc684
  • arm64: sha256:85ee233d90b52b3c012e3de2214fa7b4e8cc4048fd18c5f99618cecc0eec6898

Could you please provide the public location of, or access instructions for:

  1. A signed provenance/attestation bundle bound to the exact index or architecture-specific image manifests.
  2. The corresponding SBOM, also bound to the relevant digest(s).
  3. Public verification material and the expected producer/signer identity.
  4. Any applicable trust-policy, key/certificate lifecycle, or revocation documentation needed to verify the evidence correctly.

We found the OCI-attached in-toto/SLSA statement payloads, but they did not include a signed envelope, certificate, or verification bundle. Authenticated queries to the GitHub repository- and organization-level artifact-attestation endpoints returned 404 for the three digests above. We are not treating those responses as proof that attestations do not exist.

If these artifacts live elsewhere or require a specific public permission/API route, please let us know.

We are not requesting secrets, private keys, account credentials, or access to private infrastructure.

Thank you.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions