xyops 1.0.82
Imagen · Workflow · standard · v1.0.82
xyops, a workflow-automation and server-monitoring system (job scheduler, monitors, alerting, ticketing) by the creator of Cronicle. Built from source on Wolfi nodejs-22 (native better-sqlite3), nonroot on a hardened read-only-rootfs base. Single-instance with an embedded SQLite store on a persistent volume; the chart runs it as a StatefulSet.
Versión
La línea más reciente vive en la página base; las líneas más antiguas tienen su propia página para que puedas fijar y verificar exactamente esa versión.
Versiones publicadas
13 etiquetasCada etiqueta es un índice multiarquitectura (amd64 + arm64) fijado por digest. Etiquetada por versión, nunca :latest.
| Versión | Tamaño | Publicada | Digest |
|---|---|---|---|
| 1.0.90última | 85.2 MB | 2026-08-26 | sha256:dd7d8bf3b654… |
| 1.0.86 | 85.0 MB | 2026-07-30 | sha256:ee7074c8201e… |
| 1.0.85 | 84.9 MB | 2026-07-23 | sha256:8ea4b7a795a6… |
| 1.0.84 | 84.9 MB | 2026-07-21 | sha256:a21fa8fa3ccc… |
| 1.0.82 | 84.8 MB | 2026-07-15 | sha256:58f66abf3fe9… |
| 1.0.81 | 84.8 MB | 2026-07-12 | sha256:e688972d19d3… |
| 1.0.80 | 84.7 MB | 2026-07-09 | sha256:86ddeb5951b8… |
| 1.0.79 | 84.8 MB | 2026-07-08 | sha256:3453a6b0d4e2… |
| 1.0.78 | 84.8 MB | 2026-07-07 | sha256:9feed9379476… |
| 1.0.77 | 84.7 MB | 2026-07-05 | sha256:869a5ec20403… |
| 1.0.76 | 84.7 MB | 2026-07-04 | sha256:ffcfca8b7130… |
| 1.0.75 | 84.7 MB | 2026-07-04 | sha256:96414454dfd4… |
| 1.0.74 | 84.7 MB | 2026-07-04 | sha256:8ffa00fe1229… |
Informe de seguridad (Trivy)
Descarga la imagen
Ejecútala directamente con Docker, Podman o cualquier carga de trabajo de Kubernetes. Sin root, sistema de archivos raíz de solo lectura, compilada para amd64 y arm64.
Descargar (etiqueta)
docker pull ghcr.io/quenchworks/images/xyops:1.0.82Etiquetas
Las imágenes se etiquetan por versión de la app (nunca :latest): un índice multiarquitectura más etiquetas por arquitectura.
- Versión de la app
- 1.0.82
- Arquitecturas
- amd64, arm64
- Se ejecuta como
- nonroot (uid 1001)
- Sistema de archivos raíz
- solo lectura
- Licencia
- BSD-3-Clause
Verifica la cadena de suministro
Esta imagen está firmada con cosign y lleva un SBOM SPDX y una atestación de procedencia de compilación SLSA en el mismo digest. Comprueba las tres tú mismo:
# 1. signature — built and signed by QuenchWorks CI
cosign verify ghcr.io/quenchworks/images/xyops:1.0.82 \
--certificate-identity-regexp 'https://github.com/quenchworks/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 2. SLSA build provenance — which workflow built it, from what
cosign verify-attestation --type https://slsa.dev/provenance/v1 ghcr.io/quenchworks/images/xyops:1.0.82 \
--certificate-identity-regexp 'https://github.com/quenchworks/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 3. SPDX SBOM — the package inventory
cosign verify-attestation --type https://spdx.dev/Document/v2.3 ghcr.io/quenchworks/images/xyops:1.0.82 \
--certificate-identity-regexp 'https://github.com/quenchworks/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.comConsulta la guía de SBOM y procedencia para leer el SBOM y usar estas comprobaciones en CI.
Transparencia
Cada imagen lleva su SBOM y su procedencia como atestaciones en el mismo digest, verificables públicamente con los comandos anteriores (comprueban el paquete y el registro de transparencia de Sigstore, Rekor).
Proyecto original: https://github.com/pixlcore/xyops