Trust center
Why you can trust an OCImend image
A fixed image is only useful if you can prove it is what it claims to be. OCImend publishes the evidence with every image, signed, so it can be checked with standard tools without trusting OCImend.
Live, across the registry
Independent cross-check numbers appear here as images are rebuilt.
How every image is verified
Pinned to its original
Built from the upstream image by digest, never a moving tag. The provenance attestation records which one.
Rescanned, and cross-checked
OCImend rescans the new image, and independent open-source scanners (Trivy, Grype; govulncheck for rebuilt Go programs) scan it before and after. Their results are published and signed.
Started like the original
The new image is started side by side with the original and checked; one that does not behave the same is never published.
Refused when not better
A build that removes nothing, or adds more vulnerabilities than it fixes, is withheld with the reason.
Signed and logged
Every published image and its attestations are signed with OCImend's key and recorded in the public Sigstore transparency log.
Reproducible
Each fix comes with a Dockerfile of its final steps, so you can rebuild it in your own pipeline and compare.
What OCImend never does
- Keep registry passwords or tokens: they are used for the one request and discarded.
- Publish an image scanned with credentials: private images stay private.
- Change your application's code: only operating system packages, language packages and rebuilt programs with fixed dependencies.
- Store visitors' IP addresses.
The signing key
Fingerprint (SHA-256) 696695dc49df1591cc67427f692ba7e3dba2b6e359b03e488fd0d5c669e94740 · ocimend.io/cosign.pub
Report a security problem
See security.txt. Please do not test against other people's images.
Who runs OCImend
OCImend is built and operated by CloudTrace. About OCImend →