Alpha.16 · open source · customer-controlled

Review the extension.
Before admission.

PgExtAssure turns an exact PostgreSQL extension source snapshot into portable, independently verifiable evidence before the extension is allowlisted, built, or installed.

No account, hosted service, telemetry, or introductory meeting required.

pre-admission / policy gate offline-capable
01
Inspect approved sourceMetadata · SQL paths · native-code indicators
static
02
Apply organization policyVersioned controls · deterministic outcomes
review
03
Verify evidenceSource manifest · report · limited SPDX inventory
verify
Admission authority stays with your team.

Release 0.1.0-alpha.16 · Apache-2.0

3successful independent workflow runs
16 / 16pinned public projects processed by alpha.15
2,114files analyzed in the alpha.15 corpus
Inspect every record

Public runs, exact limits, no borrowed trust.

Three external engineers ran the same unmodified, digest-bound alpha.16 protocol in forks they controlled. The records demonstrate bounded reproducibility—not certification, customer adoption, or employer endorsement.

An allowlist says what may be installed. It rarely preserves why.

PostgreSQL extension packages can combine privileged installation and upgrade SQL, control metadata, and code that runs inside the database server process. The decision to admit one is consequential—and often assembled manually.

PgExtAssure adds a repeatable static gate before that decision, so reviewers can work from pinned inputs, explicit policy, and independently verifiable artifacts.

From source snapshot to reviewable decision evidence.

01

Inventory the trust boundary

Inspect extension metadata, install and upgrade SQL paths, native-code indicators, and other security-relevant patterns.

02

Enforce your policy

Apply an organization-owned policy, retain findings for review, and fail CI at the threshold your team selects.

03

Carry evidence forward

Create evidence bundles, optional corporate-key signatures, trust-policy evaluations, and admission receipts.

Designed for customer-controlled infrastructure.

The default evaluation model runs in your CI, self-hosted runner, or isolated environment. PgExtAssure does not intentionally send source, findings, or telemetry to a PgExtAssure service.

Read the evidence model

Review evidence, not a safety certificate.

PgExtAssure does

  • Statically inspect approved extension source trees
  • Produce deterministic, machine-readable review artifacts
  • Support CI gates and customer-owned policy
  • Make limitations and skipped coverage visible

PgExtAssure does not

  • Build, load, install, or execute the scanned extension
  • Prove an extension is safe or free of vulnerabilities
  • Replace expert review, runtime testing, or provenance checks
  • Make the final admission decision for your organization

Current stage: PgExtAssure is alpha software with multiple independent external reproductions. No customer adoption, security certification, compliance certification, or production-safety claim is made.

Test one real admission decision—mostly asynchronously.

A fixed ten-business-day evaluation covers one bounded extension scope, one organization policy, one customer-controlled integration path, verified evidence, an independent rerun, and a written limitations report.

  • No introductory meeting required
  • No PgExtAssure-hosted service required
  • Public and private request paths are separate
See scope and start

Boris Shestakov
Independent Developer
boris@shbb.pro