OCImendby CloudTrace

For platform & security teams

Fixed images that fit how you already ship

Nobody re-points a fleet of clusters at someone else's registry for a patch. OCImend hands the fix back in the forms your platform already runs on: an image in your registry, a diff for your manifests, a Dockerfile your CI can rebuild, and a pull request to the Dockerfile that started it.

Fix an image, free → See the four paths

  1. 01Scanany registry, private ones with a token used once
  2. 02Fixupgraded, rebuilt, rescanned, started side by side
  3. 03Adoptyour registry, your manifests, your Dockerfile
  4. 04Stay fixedwatched and rebuilt when new fixes ship

Four ways to adopt a fix

1

Keep your registry

Promote the fixed image into the registry your clusters already pull from, by digest, multi-arch intact. Same repository, a new tag: nothing new to allow-list.

crane copy ocimend.io/nginx:1.27-fixed \
  registry.acme.io/platform/nginx:1.27-fixed
2

Roll it out your way

The fix page writes the change for the tool you deploy with: a kustomize image override, a Helm value, or kubectl set image. Reviewable in Git, reversible in one commit.

images:
- name: nginx
  newName: registry.acme.io/platform/nginx
  digest: sha256:…
3

Patch as code

Download Dockerfile.ocimend: the original pinned by digest, the exact package upgrades, Go programs rebuilt from their own source with a patched toolchain. Build and sign it in your own pipeline.

FROM docker.io/library/mariadb@sha256:…
USER 0
RUN apt-get install -y --only-upgrade libc6 …
COPY --from=go-0 /out/app /usr/local/bin/gosu
USER mysql
4

Fix the source

Give OCImend the repository and Dockerfile path. Preview the diff, then open a pull request that bumps the Go builder and adds the upgrade step, with the before/after numbers in its description.

-FROM golang:1.22-alpine AS build
+FROM golang:1.25-alpine AS build
 FROM alpine:3.20
+USER 0
+RUN apk upgrade --no-cache libssl3 libcrypto3

Always know where an image came from

Every OCImend image names its source in standard labels, and one call answers “what is this, and what changed?” for an auditor, an admission policy or an inventory job.

curl -s 'https://ocimend.io/api/provenance?image=ocimend.io/nginx:1.27-fixed'
# source reference and digest, CVEs before/after, packages upgraded, how it was verified

crane config ocimend.io/nginx:1.27-fixed | jq .config.Labels
# io.ocimend.source · org.opencontainers.image.base.name · org.opencontainers.image.base.digest

Who gets what

TeamGetsWithout
PlatformA fixed image promoted into the internal registry, a manifest change per clustera new registry to trust
DevelopersA pull request to their own Dockerfile with the diff and the numbersa ticket saying “fix 138 CVEs”
SecurityBefore/after reports, VEX for code that is not in the program, a CI gatea spreadsheet of exceptions
AuditProvenance by digest, SBOMs in SPDX and CycloneDXguessing which image is which

Questions

Do our clusters have to pull from ocimend.io?
No. Copy the fixed image into your own registry under your own name, by digest, with one command. Pods keep pulling from the registry they already trust; only the digest changes.
Can we rebuild the fix ourselves?
Yes. Every fix comes with Dockerfile.ocimend: the original image pinned by digest plus the exact upgrade and rebuild steps. Build it in your own CI, sign it and push it wherever you like.
Can the fix go back into our Dockerfile?
Yes. Point OCImend at the repository and path, preview the diff, then open a pull request that bumps the builder image and adds the upgrade step. The token is used once for that request and never stored.
How do we know which image a fixed image came from?
Each image carries the source reference and digest in its labels (io.ocimend.source, org.opencontainers.image.base.name and base.digest), and /api/provenance?image=… returns the source, what changed and how it was verified.
Are private images and scans kept private?
Yes. Scans made with credentials are never published or used for statistics, and registry tokens are used once and never stored.

Try it on an image you run in production.

Fix an image → Read the guide API & CI