For platform & security teams
Fixed images that fit how you already ship
Nobody re-points a fleet of clusters at someone else's registry for a patch. OCImend hands the fix back in the forms your platform already runs on: an image in your registry, a diff for your manifests, a Dockerfile your CI can rebuild, and a pull request to the Dockerfile that started it.
Fix an image, free → See the four paths
- 01Scanany registry, private ones with a token used once
- 02Fixupgraded, rebuilt, rescanned, started side by side
- 03Adoptyour registry, your manifests, your Dockerfile
- 04Stay fixedwatched and rebuilt when new fixes ship
Four ways to adopt a fix
Keep your registry
Promote the fixed image into the registry your clusters already pull from, by digest, multi-arch intact. Same repository, a new tag: nothing new to allow-list.
crane copy ocimend.io/nginx:1.27-fixed \ registry.acme.io/platform/nginx:1.27-fixed
Roll it out your way
The fix page writes the change for the tool you deploy with: a kustomize image override, a Helm
value, or kubectl set image. Reviewable in Git, reversible in one commit.
images: - name: nginx newName: registry.acme.io/platform/nginx digest: sha256:…
Patch as code
Download Dockerfile.ocimend: the original pinned by digest, the exact package upgrades, Go programs
rebuilt from their own source with a patched toolchain. Build and sign it in your own pipeline.
FROM docker.io/library/mariadb@sha256:… USER 0 RUN apt-get install -y --only-upgrade libc6 … COPY --from=go-0 /out/app /usr/local/bin/gosu USER mysql
Fix the source
Give OCImend the repository and Dockerfile path. Preview the diff, then open a pull request that bumps the Go builder and adds the upgrade step, with the before/after numbers in its description.
-FROM golang:1.22-alpine AS build +FROM golang:1.25-alpine AS build FROM alpine:3.20 +USER 0 +RUN apk upgrade --no-cache libssl3 libcrypto3
Always know where an image came from
Every OCImend image names its source in standard labels, and one call answers “what is this, and what changed?” for an auditor, an admission policy or an inventory job.
curl -s 'https://ocimend.io/api/provenance?image=ocimend.io/nginx:1.27-fixed' # source reference and digest, CVEs before/after, packages upgraded, how it was verified crane config ocimend.io/nginx:1.27-fixed | jq .config.Labels # io.ocimend.source · org.opencontainers.image.base.name · org.opencontainers.image.base.digest
Who gets what
| Team | Gets | Without |
|---|---|---|
| Platform | A fixed image promoted into the internal registry, a manifest change per cluster | a new registry to trust |
| Developers | A pull request to their own Dockerfile with the diff and the numbers | a ticket saying “fix 138 CVEs” |
| Security | Before/after reports, VEX for code that is not in the program, a CI gate | a spreadsheet of exceptions |
| Audit | Provenance by digest, SBOMs in SPDX and CycloneDX | guessing which image is which |