{"apiVersion":"provenance.aureliasrs.ca/v1","kind":"Artifact","metadata":{"digest":"sha256:img002345678901bcdef2345678901bcdef2345678901bcdef2345678901bcde","name":"aureliasrs/api:3.1.0-arm64","channel":"container-images","release":"v3.1.0","publishedAt":"2026-01-12T10:15:00Z"},"spec":{"digests":[{"algorithm":"sha256","canonical":true,"value":"img002345678901bcdef2345678901bcdef2345678901bcdef2345678901bcde"},{"algorithm":"sha512","value":"img512002345678901bcdef2345678901bcdef2345678901bcdef2345678901bcdef2345678901bcdef2345678901bcdef2345678901bcdef2345678901bcde"},{"algorithm":"blake3","value":"imgblk002345678901bcdef2345678901bcdef2345678901bcdef2345678901bc"}],"signatures":[{"algorithm":"pgp","keyFingerprint":"1234 5678 90AB CDEF 1234 5678 90AB CDEF 1234 5678","keyId":"4096R/ABCD1234","keyLocations":["https://keys.openpgp.org/vks/v1/by-fingerprint/123456789ABCDEF123456789ABCDEF1234567890","https://github.com/aureliasrs.gpg","https://keybase.io/aureliasrs"],"signature":"-----BEGIN PGP SIGNATURE-----\n\niQIzBAABCAAdFiEEEjJJCDJNR0ZNaI5VZMTtxKrPw+MFAmW6mR0ACgkQZMTtxKrP\nw+M0aH//kPN1kz37X2l2z3bX5a4gE0mubC26cihfF5nhioncZ18zgfbblkE9Yp3n\nnabh3o0YczJdhF5nhioncZ18zgfbblkE9Yp3nobh3o0YczJdhF5nhioncZ18zgfb\nblkE9Yp3nobh3o0YczJdhF5nhioncZ18zgfbblkE9Yp3nobh3o0YczJdhF5nhiop\ncZ18zgfbblkE9Yp3nobh3o0YczJdhF5nhioncZ18zgfbblkE9Yp3nobh3o0Y\n=a64g\n-----END PGP SIGNATURE-----\n","signedAt":"2026-01-12T10:15:00Z","signerId":"AureliaSRS Primary Key"},{"algorithm":"pgp","keyFingerprint":"9876 5432 10FE DCBA 9876 5432 10FE DCBA 9876 5432","keyId":"2048R/WXYZ9876","keyLocations":["https://keys.openpgp.org/vks/v1/by-fingerprint/987654321FEDCBA987654321FEDCBA9876543210"],"signature":"-----BEGIN PGP SIGNATURE-----\n\niQEzBAABCAAdFiEEMNOPQRSTUVWXYZabcMTuRSvQxPQFAmW6mR8ACgkQcMTuRSvQ\nxPSGNl//lQO2l04AY3m3z4cY6a5hF1nuZcB7dijgG6ohjopdaB9ahgccmkFA0Zq4o\nobci4p1ZdaKeiG6ohjopdaB9ahgccmkFA0Zq4opcj4p1ZdaKeiG6ohjopdaB9ahg\nccmkFA0Zq4opcj4p1ZdaKeiG6ohjopdaB9ahgccmkFA0Zq4opcj4p1ZdaKeiG6oh\njopdaB9ahgccmkFA0Zq4opcj4p1ZdaKeiG6ohjopdaB9ahgccmkFA0Zq4o\n=b75h\n-----END PGP SIGNATURE-----\n","signedAt":"2026-01-12T10:16:00Z","signerId":"AureliaSRS Backup Key"}],"externalAttestations":[{"attesterId":"Sigstore Rekor","logUrl":"https://rekor.sigstore.dev/api/v1/log/entries/j005l6m0j7n89i0k","statement":"Container image logged in Sigstore Rekor transparency log","timestamp":"2026-01-12T10:20:00Z","type":"transparency-log"},{"attesterId":"Trivy Security Scanner","reportUrl":"https://example.com/scan-reports/img002345678","statement":"No critical or high vulnerabilities detected","timestamp":"2026-01-12T10:30:00Z","type":"vulnerability-scan"},{"attesterId":"Cosign","logUrl":"https://rekor.sigstore.dev/api/v1/log/entries/j005l6m0j7n89i0k-cosign","statement":"Container signature verified via Cosign","timestamp":"2026-01-12T10:20:00Z","type":"image-signature"}],"provenance":{"buildMetadata":{"baseImage":"alpine:3.19","baseImageDigest":"sha256:c5b1261d6d3e43071626931fc004f70149baeba2c8ec672bd4f27761f8e1ad6b","buildFlags":"--platform linux/arm64 --provenance mode=max --sbom=true","buildTool":"Docker Buildx","completedAt":"2026-01-12T10:10:00Z","reproducible":true,"startedAt":"2026-01-12T09:50:00Z"},"buildSystem":{"commit":"7c6d5e4f3210fedcba0987654321fedcba098765","ref":"refs/tags/v3.1.0","repository":"https://github.com/aureliasrs/api-service","type":"github-actions","workflow":".github/workflows/docker-build.yaml"},"builder":{"id":"Docker Buildx","url":"https://github.com/aureliasrs/api-service/actions/runs/89012","version":"v0.12.1"},"jurisdiction":{"buildLocation":"ca-central-1 (AWS Canada)","dataResidency":"Canada","legalEntity":"AureliaSRS Inc."},"sbom":{"digest":"sha256:sbomimg002345678901bcdef2345678901bcdef2345678901bcdef2345678901","format":"cyclonedx","url":"https://provenance.aureliasrs.ca/sbom/sha256:img002345678.json"},"signingSystem":{"jurisdiction":"Canada","keyManagement":"hardware-security-module","type":"gpg"},"slsa":{"builderLevel":3,"invocation":{"configSource":{"digest":{"sha256":"7c6d5e4f3210fedcba0987654321fedcba098765"},"entryPoint":".github/workflows/docker-build.yaml","uri":"git+https://github.com/aureliasrs/api-service@refs/tags/v3.1.0"}},"level":3,"materials":[{"digest":{"sha256":"7c6d5e4f3210fedcba0987654321fedcba098765"},"uri":"git+https://github.com/aureliasrs/api-service@refs/tags/v3.1.0"}]}},"verification":{"attestationsVerified":true,"digestVerified":true,"lastVerifiedAt":"2026-01-16T06:00:00Z","signatureVerified":true,"verificationLog":"https://provenance.aureliasrs.ca/verification-logs/img002345678.txt","verificationMethod":"automated"}},"links":{"html":"/channels/container-images/releases/v3.1.0/sha256-img002345678901bcdef2345678901bcdef2345678901bcdef2345678901bcde/","release":"/channels/container-images/releases/v3.1.0/","channel":"/channels/container-images/releases/"}}