{"apiVersion":"provenance.aureliasrs.ca/v1","kind":"Artifact","metadata":{"digest":"sha256:img001234567890abcdef1234567890abcdef1234567890abcdef1234567890ab","name":"aureliasrs/api:3.1.0-amd64","channel":"container-images","release":"v3.1.0","publishedAt":"2026-01-12T10:15:00Z"},"spec":{"digests":[{"algorithm":"sha256","canonical":true,"value":"img001234567890abcdef1234567890abcdef1234567890abcdef1234567890ab"},{"algorithm":"sha512","value":"img512001234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890ab"},{"algorithm":"blake3","value":"imgblk001234567890abcdef1234567890abcdef1234567890abcdef1234567890"}],"signatures":[{"algorithm":"pgp","keyFingerprint":"1234 5678 90AB CDEF 1234 5678 90AB CDEF 1234 5678","keyId":"4096R/ABCD1234","keyLocations":["https://keys.openpgp.org/vks/v1/by-fingerprint/123456789ABCDEF123456789ABCDEF1234567890","https://github.com/aureliasrs.gpg","https://keybase.io/aureliasrs"],"signature":"-----BEGIN PGP SIGNATURE-----\n\niQIzBAABCAAdFiEEEjJJCDJNR0ZNaI5VZMTtxKrPw+MFAmW6mR0ACgkQZMTtxKrP\nw+MzZG//jOMzjy15V0j0z1ZV3Y2eC8ksXa04agedD3lfgmlZX96zezZzkyC7Wn1l\nlXof1m8WazHbfD3lfgmlZX96zezZzkyC7Wn1llYof1m8WazHbfD3lfgmlZX96zez\nZzkyC7Wn1llYof1m8WazHbfD3lfgmlZX96zezZzkyC7Wn1llYof1m8WazHbfD3lf\ngmlZX96zezZzkyC7Wn1llYof1m8WazHbfD3lfgmlZX96zezZzkyC7Wn1llYof1m8\nWazHbfD3lfgmlZX96zezZzkyC7Wn1llYof1m8WazHbfD3lfgmlZX96zezZ\n=Y42e\n-----END PGP SIGNATURE-----\n","signedAt":"2026-01-12T10:15:00Z","signerId":"AureliaSRS Primary Key"},{"algorithm":"pgp","keyFingerprint":"9876 5432 10FE DCBA 9876 5432 10FE DCBA 9876 5432","keyId":"2048R/WXYZ9876","keyLocations":["https://keys.openpgp.org/vks/v1/by-fingerprint/987654321FEDCBA987654321FEDCBA9876543210"],"signature":"-----BEGIN PGP SIGNATURE-----\n\niQEzBAABCAAdFiEEMNOPQRSTUVWXYZabcMTuRSvQxPQFAmW6mR8ACgkQcMTuRSvQ\nxPSFMk//kPN0kz26W1k1z2aW4Z3fD9ltYb15bhfeE4mghnmaY07zfaaakzD8Xo2m\nmZpg2n9XbzIcgE4mghnmaY07zfaaakzD8Xo2mmapg2n9XbzIcgE4mghnmaY07zfa\naakzD8Xo2mmapg2n9XbzIcgE4mghnmaY07zfaaakzD8Xo2mmapg2n9XbzIcgE4mg\nhnmaY07zfaaakzD8Xo2mmapg2n9XbzIcgE4mghnmaY07zfaaakzD8Xo2m\n=Z53f\n-----END PGP SIGNATURE-----\n","signedAt":"2026-01-12T10:16:00Z","signerId":"AureliaSRS Backup Key"}],"externalAttestations":[{"attesterId":"Sigstore Rekor","logUrl":"https://rekor.sigstore.dev/api/v1/log/entries/i004k5l9i6m78h9j","statement":"Container image logged in Sigstore Rekor transparency log","timestamp":"2026-01-12T10:20:00Z","type":"transparency-log"},{"attesterId":"Trivy Security Scanner","reportUrl":"https://example.com/scan-reports/img001234567","statement":"No critical or high vulnerabilities detected","timestamp":"2026-01-12T10:30:00Z","type":"vulnerability-scan"},{"attesterId":"Cosign","logUrl":"https://rekor.sigstore.dev/api/v1/log/entries/i004k5l9i6m78h9j-cosign","statement":"Container signature verified via Cosign","timestamp":"2026-01-12T10:20:00Z","type":"image-signature"}],"provenance":{"buildMetadata":{"baseImage":"alpine:3.19","baseImageDigest":"sha256:c5b1261d6d3e43071626931fc004f70149baeba2c8ec672bd4f27761f8e1ad6b","buildFlags":"--platform linux/amd64 --provenance mode=max --sbom=true","buildTool":"Docker Buildx","completedAt":"2026-01-12T10:10:00Z","reproducible":true,"startedAt":"2026-01-12T09:50:00Z"},"buildSystem":{"commit":"7c6d5e4f3210fedcba0987654321fedcba098765","ref":"refs/tags/v3.1.0","repository":"https://github.com/aureliasrs/api-service","type":"github-actions","workflow":".github/workflows/docker-build.yaml"},"builder":{"id":"Docker Buildx","url":"https://github.com/aureliasrs/api-service/actions/runs/89012","version":"v0.12.1"},"jurisdiction":{"buildLocation":"ca-central-1 (AWS Canada)","dataResidency":"Canada","legalEntity":"AureliaSRS Inc."},"sbom":{"digest":"sha256:sbomimg001234567890abcdef1234567890abcdef1234567890abcdef123456","format":"cyclonedx","url":"https://provenance.aureliasrs.ca/sbom/sha256:img001234567.json"},"signingSystem":{"jurisdiction":"Canada","keyManagement":"hardware-security-module","type":"gpg"},"slsa":{"builderLevel":3,"invocation":{"configSource":{"digest":{"sha256":"7c6d5e4f3210fedcba0987654321fedcba098765"},"entryPoint":".github/workflows/docker-build.yaml","uri":"git+https://github.com/aureliasrs/api-service@refs/tags/v3.1.0"}},"level":3,"materials":[{"digest":{"sha256":"7c6d5e4f3210fedcba0987654321fedcba098765"},"uri":"git+https://github.com/aureliasrs/api-service@refs/tags/v3.1.0"}]}},"verification":{"attestationsVerified":true,"digestVerified":true,"lastVerifiedAt":"2026-01-16T06:00:00Z","signatureVerified":true,"verificationLog":"https://provenance.aureliasrs.ca/verification-logs/img001234567.txt","verificationMethod":"automated"}},"links":{"html":"/channels/container-images/releases/v3.1.0/sha256-img001234567890abcdef1234567890abcdef1234567890abcdef1234567890ab/","release":"/channels/container-images/releases/v3.1.0/","channel":"/channels/container-images/releases/"}}