Skip to content
QuenchWorks

concourse

Chart · CI/CD & registry · standard · v0.0.3

digest pinnedcosign signedSPDX SBOMSLSA provenanceamd64 · arm64Rebuilt 2026-09-30

Concourse CI, built from the release tag with its web UI compiled and embedded in the one Go binary, the containerd, grpc and otel modules floated to their fixed releases. The web node (ATC and TSA) runs nonroot on a read-only rootfs against an external PostgreSQL; the worker runs privileged on Wolfi's containerd and runc with the CNI plugins built from source, and bundles the registry-image and time resource types built from their tags. The git resource type is its own image, concourse-git-resource.

Deployed image digest

sha256:3ccc486400e1a91094a70ae55fefd414ebde67515f9eb272cef1b6d2cc205a44

Chart OCI version

oci://ghcr.io/quenchworks/charts/concourse:0.0.3

The chart pins its image by this signed digest, so you never track it yourself. Signatures, SBOM, and provenance attach to the same digest.

Signed
no
SBOM
SPDX, on image
Provenance
SLSA build
Architectures
amd64, arm64
Runs as
nonroot (uid 1001)
Root filesystem
read-only
Image size
123.4 MB

Security report (Trivy)

A· 88/1006 open · no upstream fix yet

Vulnerability detail

concourse 8.3.1 · 1 CVE
CVESeverityPackageInstalledFixed inTitle
GO-2026-5932UNKNOWNgolang.org/x/cryptov0.56.0— not fixableThe golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
0
Critical
0
High
0
Medium
0
Low
6
Unknown

Security report (Trivy) · image concourse 8.3.1

Install the chart

Deploy to Kubernetes with hardened defaults. The chart pins its image by signed digest, so you never track it yourself.

Install (latest)

helm install my-concourse oci://ghcr.io/quenchworks/charts/concourse --version 0.0.3

Deploys image (digest-pinned)

ghcr.io/quenchworks/images/concourse@sha256:3ccc486400e1a91094a70ae55fefd414ebde67515f9eb272cef1b6d2cc205a44
ghcr.io/quenchworks/images/kubectl@sha256:4033ac5e5f359739cf017a256188a8da7592edae86e452c6327dc4865a66a580
ghcr.io/quenchworks/images/postgresql@sha256:48aebfed6b703fc2e8582aff8382063ea6c06b62d8b735e1b13da306182d1f50
Chart version
0.0.3
App version
8.3.1
Chart license
MIT
App license
Apache-2.0
Service port
8080
Signed
no
Values schema
no

Verify the chart

cosign verify ghcr.io/quenchworks/charts/concourse:0.0.3 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Transparency

The chart publishes its attestations on GitHub and the image it deploys carries its own on the same digest, publicly verifiable with the commands above. Both log to the Sigstore transparency log (Rekor), which cosign verify checks for you.

Upstream project: https://concourse-ci.org