PostgreSQL and supply-chain update monitor
Generated: 2026-09-14T15:14:38+00:00
| Input |
Locked/selected |
Authoritative result |
Status |
| PostgreSQL major 18 |
18.6 |
18.6 (released 2026-08-13, EOL 2030-11-14) |
current |
Authoritative PostgreSQL data: https://www.postgresql.org/versions.json
The scheduled artifact-lock workflow separately resolves both native
architectures from current PGDG and UBI metadata and verifies every downloaded
RPM, source RPM, signing-key hash/fingerprint, and base digest. Review its
artifacts and failures; automation must never accept a changed key or lock.
Dependabot and Renovate propose pinned GitHub Action, Python tool, UBI image,
Syft, Grype, Trivy, Cosign, and assurance-tool updates. Scanner databases are
refreshed by scheduled CI and release runs. Every proposal still requires the
review and qualification in docs/MAINTENANCE.md.
PostgreSQL and supply-chain update monitor
Generated:
2026-09-14T15:14:38+00:0018.618.6(released 2026-08-13, EOL 2030-11-14)Authoritative PostgreSQL data: https://www.postgresql.org/versions.json
The scheduled artifact-lock workflow separately resolves both native
architectures from current PGDG and UBI metadata and verifies every downloaded
RPM, source RPM, signing-key hash/fingerprint, and base digest. Review its
artifacts and failures; automation must never accept a changed key or lock.
Dependabot and Renovate propose pinned GitHub Action, Python tool, UBI image,
Syft, Grype, Trivy, Cosign, and assurance-tool updates. Scanner databases are
refreshed by scheduled CI and release runs. Every proposal still requires the
review and qualification in
docs/MAINTENANCE.md.