Verify an image
Don't trust us: verify every image
Every image OCImend publishes is signed, recorded in the public Sigstore transparency log, and scanned before and after by independent open-source scanners. Its provenance, SBOM, VEX, scan results and remediation record are signed attestations you can check with standard tools, or enforce in your cluster.
The signing key
Key fingerprint (SHA-256): 696695dc49df1591cc67427f692ba7e3dba2b6e359b03e488fd0d5c669e94740 · cosign.pub
Verify with cosign
cosign verify --key https://ocimend.io/cosign.pub ocimend.io/nginx:1.27-fixed cosign verify-attestation --key https://ocimend.io/cosign.pub --type slsaprovenance1 ocimend.io/nginx:1.27-fixed cosign verify-attestation --key https://ocimend.io/cosign.pub \ --type https://ocimend.io/attestations/remediation/v1 ocimend.io/nginx:1.27-fixed cosign verify-attestation --key https://ocimend.io/cosign.pub --type cyclonedx ocimend.io/nginx:1.27-fixed cosign verify-attestation --key https://ocimend.io/cosign.pub --type vuln ocimend.io/nginx:1.27-fixed
Scan it yourself
trivy image ocimend.io/nginx:1.27-fixed grype ocimend.io/nginx:1.27-fixed
Enforce it in Kubernetes
Admit only OCImend images that are signed and whose remediation record says they started like the original.
Kyverno
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: require-ocimend-verified-images
spec:
validationFailureAction: Enforce
webhookTimeoutSeconds: 30
rules:
- name: signed-and-remediated
match:
any:
- resources:
kinds: [Pod]
verifyImages:
- imageReferences: ["ocimend.io/*"]
attestors:
- entries:
- keys:
publicKeys: |-
-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEyU//jlYRTZZmDlNKg4MyqNKjQ8zv
WLLIfoDFLDaUEPRJbyoPojvFITE0pcDv0XiIB3nZGuo1mf9gPcjqbDmLTg==
-----END PUBLIC KEY-----
attestations:
- type: https://ocimend.io/attestations/remediation/v1
attestors:
- entries:
- keys:
publicKeys: |-
-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEyU//jlYRTZZmDlNKg4MyqNKjQ8zv
WLLIfoDFLDaUEPRJbyoPojvFITE0pcDv0XiIB3nZGuo1mf9gPcjqbDmLTg==
-----END PUBLIC KEY-----
conditions:
- all:
- key: "{{ runtime.started_like_original }}"
operator: Equals
value: true
Sigstore policy-controller
apiVersion: policy.sigstore.dev/v1beta1
kind: ClusterImagePolicy
metadata:
name: ocimend-verified-images
spec:
images:
- glob: "ocimend.io/**"
authorities:
- key:
data: |
-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEyU//jlYRTZZmDlNKg4MyqNKjQ8zv
WLLIfoDFLDaUEPRJbyoPojvFITE0pcDv0XiIB3nZGuo1mf9gPcjqbDmLTg==
-----END PUBLIC KEY-----
attestations:
- name: remediation
predicateType: https://ocimend.io/attestations/remediation/v1
policy:
type: cue
data: |
predicateType: "https://ocimend.io/attestations/remediation/v1"
predicate: runtime: started_like_original: true