OCImendby CloudTrace

Trust center

Why you can trust an OCImend image

A fixed image is only useful if you can prove it is what it claims to be. OCImend publishes the evidence with every image, signed, so it can be checked with standard tools without trusting OCImend.

Live, across the registry

171images in the public registry
0signed by OCImend
0recorded in the public transparency log
0independent scanners cross-checking

Independent cross-check numbers appear here as images are rebuilt.

How every image is verified

Pinned to its original

Built from the upstream image by digest, never a moving tag. The provenance attestation records which one.

Rescanned, and cross-checked

OCImend rescans the new image, and independent open-source scanners (Trivy, Grype; govulncheck for rebuilt Go programs) scan it before and after. Their results are published and signed.

Started like the original

The new image is started side by side with the original and checked; one that does not behave the same is never published.

Refused when not better

A build that removes nothing, or adds more vulnerabilities than it fixes, is withheld with the reason.

Signed and logged

Every published image and its attestations are signed with OCImend's key and recorded in the public Sigstore transparency log.

Reproducible

Each fix comes with a Dockerfile of its final steps, so you can rebuild it in your own pipeline and compare.

Verify an image →

What OCImend never does

The signing key

Fingerprint (SHA-256) 696695dc49df1591cc67427f692ba7e3dba2b6e359b03e488fd0d5c669e94740 · ocimend.io/cosign.pub

Report a security problem

See security.txt. Please do not test against other people's images.

Who runs OCImend

OCImend is built and operated by CloudTrace. About OCImend →