# Pull by digest (immutable reference)
docker pull aureliasrs/api:3.1.0-amd64@sha256:img001234567890abcdef1234567890abcdef1234567890abcdef1234567890ab
# Verify with cosign
cosign verify aureliasrs/api:3.1.0-amd64@sha256:img001234567890abcdef1234567890abcdef1234567890abcdef1234567890abSLSA 3
Builder Level: 3
Content-addressed checksums for verifying artifact integrity.
img001234567890abcdef1234567890abcdef1234567890abcdef1234567890abimg512001234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abimgblk001234567890abcdef1234567890abcdef1234567890abcdef1234567890# Download artifact
curl -O https://artifacts.patterneddesigns.ca/container-images/v3.1.0/aureliasrs/api:3.1.0-amd64
# Verify SHA-256
sha256sum aureliasrs/api:3.1.0-amd64
# Expected: img001234567890abcdef1234567890abcdef1234567890abcdef1234567890abCryptographic signatures binding this artifact to publisher identities.
4096R/ABCD12341234 5678 90AB CDEF 1234 5678 90AB CDEF 1234 5678-----BEGIN PGP SIGNATURE-----
iQIzBAABCAAdFiEEEjJJCDJNR0ZNaI5VZMTtxKrPw+MFAmW6mR0ACgkQZMTtxKrP
w+MzZG//jOMzjy15V0j0z1ZV3Y2eC8ksXa04agedD3lfgmlZX96zezZzkyC7Wn1l
lXof1m8WazHbfD3lfgmlZX96zezZzkyC7Wn1llYof1m8WazHbfD3lfgmlZX96zez
ZzkyC7Wn1llYof1m8WazHbfD3lfgmlZX96zezZzkyC7Wn1llYof1m8WazHbfD3lf
gmlZX96zezZzkyC7Wn1llYof1m8WazHbfD3lfgmlZX96zezZzkyC7Wn1llYof1m8
WazHbfD3lfgmlZX96zezZzkyC7Wn1llYof1m8WazHbfD3lfgmlZX96zezZ
=Y42e
-----END PGP SIGNATURE-----
# Import key
gpg --keyserver keys.openpgp.org --recv-keys 4096R/ABCD1234
# Verify signature
gpg --verify signature.asc artifact.tar.gz2048R/WXYZ98769876 5432 10FE DCBA 9876 5432 10FE DCBA 9876 5432-----BEGIN PGP SIGNATURE-----
iQEzBAABCAAdFiEEMNOPQRSTUVWXYZabcMTuRSvQxPQFAmW6mR8ACgkQcMTuRSvQ
xPSFMk//kPN0kz26W1k1z2aW4Z3fD9ltYb15bhfeE4mghnmaY07zfaaakzD8Xo2m
mZpg2n9XbzIcgE4mghnmaY07zfaaakzD8Xo2mmapg2n9XbzIcgE4mghnmaY07zfa
aakzD8Xo2mmapg2n9XbzIcgE4mghnmaY07zfaaakzD8Xo2mmapg2n9XbzIcgE4mg
hnmaY07zfaaakzD8Xo2mmapg2n9XbzIcgE4mghnmaY07zfaaakzD8Xo2m
=Z53f
-----END PGP SIGNATURE-----
# Import key
gpg --keyserver keys.openpgp.org --recv-keys 2048R/WXYZ9876
# Verify signature
gpg --verify signature.asc artifact.tar.gzContainer image logged in Sigstore Rekor transparency log
No critical or high vulnerabilities detected
Container signature verified via Cosign
Build metadata and supply chain context for this artifact.
Started: 2026-01-12 09:50
Completed: 2026-01-12 10:10
Reproducible: Yes
Type: gpg
Key Management: hardware-security-module
Jurisdiction: Canada
Build Location: ca-central-1 (AWS Canada)
Data Residency: Canada
Legal Entity: AureliaSRS Inc.