Audit date: 2026-09-07 UTC
Upstream: duckdb/pg_duckdb
Source snapshot: ee38d3b540ecea1d93683ba99bdcec5632a21eaf, the tip of the default main branch
Audit date: 2026-09-07 UTC
Upstream: duckdb/pg_duckdb
Source snapshot: ee38d3b540ecea1d93683ba99bdcec5632a21eaf, the tip of the default main branch
Audit date: 2026-09-07 UTC
Upstream: CrunchyData/pg_parquet
Source snapshot: 44f7eb8777275829c19bde19441046c551b692ea, the tip of the default main branch
Implement this on top of PR 61 at verified head 7828a03863dd0b3750dd75f2915765b07638f9e7 (2026-09-07). PR 61 provides the filesystem-SBOM, ScanCode, composition-manifest, local-act, and attestation primitives for the Debian extension images. The pgrx implementation is a sibling build path; existing Debian Dockerfiles, Bake definitions, workflows, and packaging behavior should remain unchanged.
Recommended design
This proposal defines how to build and publish a CloudNativePG (CNPG) ImageVolume extension image from a Rust pgrx project using GitHub Actions, with clear dependency inventory, license documentation, vulnerability traceability, provenance, and attestations.
The release source is selected by a GitHub release version tag. The source tree includes a committed Cargo.lock.
| CREATE OR REPLACE FUNCTION sanatize_sql(sql_text text) | |
| RETURNS text AS $$ | |
| DECLARE | |
| cleaned_text text; | |
| first_part_regex_3words text := '([^[:space:]]+)[[:space:]]+([^[:space:]]+)[[:space:]]+([^[:space:]]+)'; | |
| first_part_regex_2words text := '([^[:space:]]+)[[:space:]]+([^[:space:]]+)'; | |
| first_part_regex_1words text := '([^[:space:]]+)'; | |
| first_part text; | |
| match_array text; | |
| from_parts_regex_3words text := '(FROM)[[:space:]]+([^[:space:]]+)[[:space:]]*([^[:space:]]*)'; |
| tcping myaksclust-myresourcegroup-c33803-9kibbvlt.hcp.eastus.azmk8s.io 443 | |
| seq 0: tcp response from 20.121.80.211 [open] 75.465 ms | |
| seq 1: tcp response from 20.121.80.211 [open] 75.355 ms | |
| seq 2: tcp response from 20.121.80.211 [open] 75.230 ms | |
| seq 3: tcp response from 20.121.80.211 [open] 79.054 ms | |
| seq 4: tcp response from 20.121.80.211 [open] 75.140 ms | |
| ^C | |
| time kubectl get pods | |
| No resources found in default namespace. |
| #!/bin/bash | |
| # Ubuntu 25.04 Desktop Setup Script | |
| # This script is intended to run on a freshly installed Ubuntu 25.04 server | |
| # It installs the desktop environment and xRDP for remote desktop access | |
| # | |
| # WARNING: This script enables remote desktop access which may have security implications | |
| # Make sure to use strong passwords and consider firewall rules | |
| # | |
| # Example usage: | |
| # curl -sSL bit.ly/ubuntu2504desktop -O |
| cat jtest.go | |
| package main | |
| import ( | |
| "encoding/json" | |
| "fmt" | |
| cnpg "github.com/cloudnative-pg/cloudnative-pg/api/v1" // Import the CNPG API types | |
| ) |
| #### tested on r6i.16xlarge with RDS Postgres | |
| pgbench -i -s 10 --foreign-keys | |
| pgbench -N -M prepared -T 360 -P 5 -c 512 -j 8 | |
| psql -c "create extension pageinspect" | |
| psql <<EOF | |
| -- this query will return one row for each SLRU page. |
| #!/bin/bash | |
| INIT_TABLE_ROWS=20000000 | |
| PGBENCH_TRANSACTIONS_PER_CLIENT=100000 | |
| PGBENCH_CLIENTS=10 | |
| run_test() { | |
| echo "$(date +%y%m%d.%H%M) STARTING TEST $1" | |
| pg_stop |