OCImendby CloudTrace

Documentation

The OCImend agent and command line

One binary, ocimend, that finds and fixes known vulnerabilities in container images where they live: your registry, your builder, your signing key, your repositories.

Install

curl -fsSL https://ocimend.io/downloads/agent/install.sh | sh
ocimend login --key ocm_…          # an API key from the console

Linux and macOS (amd64, arm64) and Windows (amd64): all downloads. The installer checks the checksum, and the signature too when cosign is installed.

Scan

ocimend scan registry.acme.example/team/api:1.4
ocimend scan registry.acme.example/team/api:1.4 --fail-on critical          # exit 3 on findings, for CI
ocimend scan registry.acme.example/team/api:1.4 --format sarif -o ocimend.sarif   # also cbom, spdx, openvex, json

Private registries use your existing docker login and credential helpers (ECR, GCR/GAR, ACR), or OCIMEND_REGISTRY_USERNAME and OCIMEND_REGISTRY_PASSWORD. Local images: oci:DIR or archive:FILE.tar.

Fix

ocimend fix registry.acme.example/team/api:1.4 \
  --push registry.acme.example/team/api:1.4-fixed \
  --sign-key awskms:///alias/image-signing \
  --smoke 10s \
  --pr acme/api --pr-path deploy/Dockerfile.ocimend   # GITHUB_TOKEN, used on this machine only
  1. The image is read here; its inventory goes to OCImend.
  2. The fix comes back as finished build steps (which packages, from which version to which).
  3. Your builder (docker, podman or buildah) builds it; the agent reads the result.
  4. The release gate compares the two: fewer known vulnerabilities, nothing critical or actively exploited introduced, and with --smoke the image starts like the original.
  5. Only then: pushed to your registry, signed with your key (with the remediation record attached), and the pull request opened.

Just the change, for your own pipeline: ocimend fix IMAGE --dockerfile-only Dockerfile.ocimend. Exit codes: 0 done, 3 findings at --fail-on, 4 the release gate refused the image, 5 the fix needs the OCImend cloud build.

Run it as an agent

export OCIMEND_API_KEY=ocm_…      # an agent key from the console
ocimend agent run --name prod-eu

The agent asks for work over HTTPS and reports results: start scans and fixes from the console. In Kubernetes, run it as one non-root pod with a read-only filesystem, no service-account token and egress on 443 only (manifest included with the agent). Fix jobs need an image builder, so run those agents on a CI runner or build host.

What it sends

SentNever sent
Image reference and digest, layer digests and sizesImage layers, or the content of any file
OS release fields (name, version)Environment variables, configuration files, secrets
Installed package names and versionsRegistry credentials
Application dependency names, versions and pathsYour signing key
Go modules compiled into each programYour source-control token
Interpreter paths, whether a shell is presentLabels other than the standard OCI ones

More on security and data handling.

Options

SettingWhat it does
OCIMEND_API_KEYAPI key (or ocimend login)
OCIMEND_URLservice address (default https://ocimend.io)
--platformplatform to read from a multi-platform image (default linux/amd64)
--builder, --build-networkwhich builder to use; the build's network (e.g. host, behind a proxy)
--tlogalso record signatures in the public transparency log (off by default)
--github-apiGitHub Enterprise Server API address