CLI 2.118.0 selects supabase/postgres:17.6.1.171 for a local PostgreSQL 17 project. The September 25 security advisory describes fixes in PostgreSQL 17.11. GitHub has a standard 17.11.0.001 source release with upstream 17.11 in nix/config.nix, but manifest lookup for that exact standard tag failed on Docker Hub, public ECR and GHCR. A Docker Hub name=17.11 tag query returned only OrioleDB variants.
Which official standard PostgreSQL image tag/digest supports linux/arm64, contains those security fixes, and is compatible with local Supabase CLI? Is there a supported CLI release or per-project pin procedure for it? Alternatively, is there patch/backport evidence for the CLI's current default image?
We have not started this local stack and are not requesting a custom build or an engine change. These observations do not assert that any hosted project is vulnerable.
CLI 2.118.0 selects
supabase/postgres:17.6.1.171for a local PostgreSQL 17 project. The September 25 security advisory describes fixes in PostgreSQL 17.11. GitHub has a standard17.11.0.001source release with upstream 17.11 innix/config.nix, but manifest lookup for that exact standard tag failed on Docker Hub, public ECR and GHCR. A Docker Hubname=17.11tag query returned only OrioleDB variants.Which official standard PostgreSQL image tag/digest supports linux/arm64, contains those security fixes, and is compatible with local Supabase CLI? Is there a supported CLI release or per-project pin procedure for it? Alternatively, is there patch/backport evidence for the CLI's current default image?
We have not started this local stack and are not requesting a custom build or an engine change. These observations do not assert that any hosted project is vulnerable.