Documentation
The OCImend agent and command line
One binary, ocimend, that finds and fixes known vulnerabilities in container images
where they live: your registry, your builder, your signing key, your repositories.
Install
curl -fsSL https://ocimend.io/downloads/agent/install.sh | sh
ocimend login --key ocm_… # an API key from the console
Linux and macOS (amd64, arm64) and Windows (amd64): all downloads. The installer checks the checksum, and the signature too when cosign is installed.
Scan
ocimend scan registry.acme.example/team/api:1.4 ocimend scan registry.acme.example/team/api:1.4 --fail-on critical # exit 3 on findings, for CI ocimend scan registry.acme.example/team/api:1.4 --format sarif -o ocimend.sarif # also cbom, spdx, openvex, json
Private registries use your existing docker login and credential helpers (ECR, GCR/GAR, ACR), or
OCIMEND_REGISTRY_USERNAME and OCIMEND_REGISTRY_PASSWORD. Local images: oci:DIR
or archive:FILE.tar.
Fix
ocimend fix registry.acme.example/team/api:1.4 \
--push registry.acme.example/team/api:1.4-fixed \
--sign-key awskms:///alias/image-signing \
--smoke 10s \
--pr acme/api --pr-path deploy/Dockerfile.ocimend # GITHUB_TOKEN, used on this machine only
- The image is read here; its inventory goes to OCImend.
- The fix comes back as finished build steps (which packages, from which version to which).
- Your builder (docker, podman or buildah) builds it; the agent reads the result.
- The release gate compares the two: fewer known vulnerabilities, nothing critical or actively exploited
introduced, and with
--smokethe image starts like the original. - Only then: pushed to your registry, signed with your key (with the remediation record attached), and the pull request opened.
Just the change, for your own pipeline: ocimend fix IMAGE --dockerfile-only Dockerfile.ocimend.
Exit codes: 0 done, 3 findings at --fail-on, 4 the release gate refused the image, 5 the fix needs the
OCImend cloud build.
Run it as an agent
export OCIMEND_API_KEY=ocm_… # an agent key from the console
ocimend agent run --name prod-eu
The agent asks for work over HTTPS and reports results: start scans and fixes from the console. In Kubernetes, run it as one non-root pod with a read-only filesystem, no service-account token and egress on 443 only (manifest included with the agent). Fix jobs need an image builder, so run those agents on a CI runner or build host.
What it sends
| Sent | Never sent |
|---|---|
| Image reference and digest, layer digests and sizes | Image layers, or the content of any file |
| OS release fields (name, version) | Environment variables, configuration files, secrets |
| Installed package names and versions | Registry credentials |
| Application dependency names, versions and paths | Your signing key |
| Go modules compiled into each program | Your source-control token |
| Interpreter paths, whether a shell is present | Labels other than the standard OCI ones |
More on security and data handling.
Options
| Setting | What it does |
|---|---|
OCIMEND_API_KEY | API key (or ocimend login) |
OCIMEND_URL | service address (default https://ocimend.io) |
--platform | platform to read from a multi-platform image (default linux/amd64) |
--builder, --build-network | which builder to use; the build's network (e.g. host, behind a proxy) |
--tlog | also record signatures in the public transparency log (off by default) |
--github-api | GitHub Enterprise Server API address |