Provenance Registry Artifact Attestation
ARTIFACT

aureliasrs/api:3.1.0-amd64

container-images / v3.1.0 / aureliasrs/api:3.1.0-amd64
Published:

OCI Image Details

# Pull by digest (immutable reference)
docker pull aureliasrs/api:3.1.0-amd64@sha256:img001234567890abcdef1234567890abcdef1234567890abcdef1234567890ab

# Verify with cosign
cosign verify aureliasrs/api:3.1.0-amd64@sha256:img001234567890abcdef1234567890abcdef1234567890abcdef1234567890ab

SLSA Provenance

SLSA 3

Builder Level: 3

Digests

Content-addressed checksums for verifying artifact integrity.

img001234567890abcdef1234567890abcdef1234567890abcdef1234567890ab
img512001234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890ab
imgblk001234567890abcdef1234567890abcdef1234567890abcdef1234567890
# Download artifact
curl -O https://artifacts.patterneddesigns.ca/container-images/v3.1.0/aureliasrs/api:3.1.0-amd64

# Verify SHA-256
sha256sum aureliasrs/api:3.1.0-amd64
# Expected: img001234567890abcdef1234567890abcdef1234567890abcdef1234567890ab

Signatures & Trust

Cryptographic signatures binding this artifact to publisher identities.

AureliaSRS Primary Key
pgp
4096R/ABCD1234
1234 5678 90AB CDEF 1234 5678 90AB CDEF 1234 5678
-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEEjJJCDJNR0ZNaI5VZMTtxKrPw+MFAmW6mR0ACgkQZMTtxKrP
w+MzZG//jOMzjy15V0j0z1ZV3Y2eC8ksXa04agedD3lfgmlZX96zezZzkyC7Wn1l
lXof1m8WazHbfD3lfgmlZX96zezZzkyC7Wn1llYof1m8WazHbfD3lfgmlZX96zez
ZzkyC7Wn1llYof1m8WazHbfD3lfgmlZX96zezZzkyC7Wn1llYof1m8WazHbfD3lf
gmlZX96zezZzkyC7Wn1llYof1m8WazHbfD3lfgmlZX96zezZzkyC7Wn1llYof1m8
WazHbfD3lfgmlZX96zezZzkyC7Wn1llYof1m8WazHbfD3lfgmlZX96zezZ
=Y42e
-----END PGP SIGNATURE-----
# Import key
gpg --keyserver keys.openpgp.org --recv-keys 4096R/ABCD1234

# Verify signature
gpg --verify signature.asc artifact.tar.gz
AureliaSRS Backup Key
pgp
2048R/WXYZ9876
9876 5432 10FE DCBA 9876 5432 10FE DCBA 9876 5432
-----BEGIN PGP SIGNATURE-----

iQEzBAABCAAdFiEEMNOPQRSTUVWXYZabcMTuRSvQxPQFAmW6mR8ACgkQcMTuRSvQ
xPSFMk//kPN0kz26W1k1z2aW4Z3fD9ltYb15bhfeE4mghnmaY07zfaaakzD8Xo2m
mZpg2n9XbzIcgE4mghnmaY07zfaaakzD8Xo2mmapg2n9XbzIcgE4mghnmaY07zfa
aakzD8Xo2mmapg2n9XbzIcgE4mghnmaY07zfaaakzD8Xo2mmapg2n9XbzIcgE4mg
hnmaY07zfaaakzD8Xo2mmapg2n9XbzIcgE4mghnmaY07zfaaakzD8Xo2m
=Z53f
-----END PGP SIGNATURE-----
# Import key
gpg --keyserver keys.openpgp.org --recv-keys 2048R/WXYZ9876

# Verify signature
gpg --verify signature.asc artifact.tar.gz
Sigstore Rekor transparency-log

Container image logged in Sigstore Rekor transparency log

Trivy Security Scanner vulnerability-scan

No critical or high vulnerabilities detected

Cosign image-signature

Container signature verified via Cosign

Provenance

Build metadata and supply chain context for this artifact.

Docker Buildx

OS: v0.12.1

View Build

Type: github-actions

Workflow: .github/workflows/docker-build.yaml

Commit: 7c6d5e4f

Repository

Started: 2026-01-12 09:50

Completed: 2026-01-12 10:10

Reproducible: Yes

Format: cyclonedx

Digest: sha256:sbomimg001234...

Download SBOM

Type: gpg

Key Management: hardware-security-module

Jurisdiction: Canada

Build Location: ca-central-1 (AWS Canada)

Data Residency: Canada

Legal Entity: AureliaSRS Inc.

Verification

Verification Passed
Digest Verified:
Signature Verified:
Attestations Verified:
Last Verified:
Method: automated
View Verification Log
Verification results are derived and informational. Always perform independent verification using the signatures and digests above.