{"apiVersion":"provenance.aureliasrs.ca/v1","kind":"Artifact","metadata":{"digest":"sha256:img003456789012cdef3456789012cdef3456789012cdef3456789012cdef34","name":"aureliasrs/api:3.1.0","channel":"container-images","release":"v3.1.0","publishedAt":"2026-01-12T10:15:00Z"},"spec":{"digests":[{"algorithm":"sha256","canonical":true,"value":"img003456789012cdef3456789012cdef3456789012cdef3456789012cdef34"},{"algorithm":"sha512","value":"img512003456789012cdef3456789012cdef3456789012cdef3456789012cdef3456789012cdef3456789012cdef3456789012cdef3456789012cdef34"},{"algorithm":"blake3","value":"imgblk003456789012cdef3456789012cdef3456789012cdef3456789012cdef"}],"signatures":[{"algorithm":"pgp","keyFingerprint":"1234 5678 90AB CDEF 1234 5678 90AB CDEF 1234 5678","keyId":"4096R/ABCD1234","keyLocations":["https://keys.openpgp.org/vks/v1/by-fingerprint/123456789ABCDEF123456789ABCDEF1234567890","https://github.com/aureliasrs.gpg","https://keybase.io/aureliasrs"],"signature":"-----BEGIN PGP SIGNATURE-----\n\niQIzBAABCAAdFiEEEjJJCDJNR0ZNaI5VZMTtxKrPw+MFAmW6mR0ACgkQZMTtxKrP\nw+M1bI//lQP2l15BY4n4z5dZ7b6iF2ovcD37ekjhH7pjkpqeB290hihddnlGB1as5p\npcdk5q2aeblfjH7pjkpqeB290hihddnlGB1as5qqddk5q2aeblfjH7pjkpqeB290\nhihddnlGB1as5qqddk5q2aeblfjH7pjkpqeB290hihddnlGB1as5qqddk5q2aebl\nfjH7pjkpqeB290hihddnlGB1as5qqddk5q2aeblfjH7pjkpqeB290hihddnlG\n=c86i\n-----END PGP SIGNATURE-----\n","signedAt":"2026-01-12T10:15:00Z","signerId":"AureliaSRS Primary Key"},{"algorithm":"pgp","keyFingerprint":"9876 5432 10FE DCBA 9876 5432 10FE DCBA 9876 5432","keyId":"2048R/WXYZ9876","keyLocations":["https://keys.openpgp.org/vks/v1/by-fingerprint/987654321FEDCBA987654321FEDCBA9876543210"],"signature":"-----BEGIN PGP SIGNATURE-----\n\niQEzBAABCAAdFiEEMNOPQRSTUVWXYZabcMTuRSvQxPQFAmW6mR8ACgkQcMTuRSvQ\nxPSHOm//mRQ3m26CZ5o5z6eaAb7jG3qwdE48fkliI8qlkrrgcC0bjijfeonHC2bt6r\nreel6r3bgcmgkI8qlkrrgcC0bjijfeonHC2bt6srel6r3bgcmgkI8qlkrrgcC0bj\nijfeonHC2bt6srel6r3bgcmgkI8qlkrrgcC0bjijfeonHC2bt6srel6r3bgcmgkI\n8qlkrrgcC0bjijfeonHC2bt6srel6r3bgcmgkI8qlkrrgcC0bjijfeonHC2b\n=d97j\n-----END PGP SIGNATURE-----\n","signedAt":"2026-01-12T10:16:00Z","signerId":"AureliaSRS Backup Key"}],"externalAttestations":[{"attesterId":"Sigstore Rekor","logUrl":"https://rekor.sigstore.dev/api/v1/log/entries/k006m7n1k8o90j1l","statement":"Multi-arch manifest logged in Sigstore Rekor transparency log","timestamp":"2026-01-12T10:20:00Z","type":"transparency-log"},{"attesterId":"Docker Hub","reportUrl":"https://hub.docker.com/r/aureliasrs/api/tags","statement":"Multi-arch manifest published to Docker Hub","timestamp":"2026-01-12T10:25:00Z","type":"container-registry"}],"provenance":{"buildMetadata":{"buildFlags":"--platform linux/amd64,linux/arm64 --provenance mode=max","buildTool":"Docker Buildx","completedAt":"2026-01-12T10:10:00Z","manifestReferences":[{"digest":"sha256:img001234567890abcdef1234567890abcdef1234567890abcdef1234567890ab","platform":"linux/amd64"},{"digest":"sha256:img002345678901bcdef2345678901bcdef2345678901bcdef2345678901bcde","platform":"linux/arm64"}],"manifestType":"OCI Image Manifest List","reproducible":false,"startedAt":"2026-01-12T09:50:00Z"},"buildSystem":{"commit":"7c6d5e4f3210fedcba0987654321fedcba098765","ref":"refs/tags/v3.1.0","repository":"https://github.com/aureliasrs/api-service","type":"github-actions","workflow":".github/workflows/docker-build.yaml"},"builder":{"id":"Docker Buildx","url":"https://github.com/aureliasrs/api-service/actions/runs/89012","version":"v0.12.1"},"jurisdiction":{"buildLocation":"ca-central-1 (AWS Canada)","dataResidency":"Canada","legalEntity":"AureliaSRS Inc."},"sbom":{"digest":"sha256:sbomimg003456789012cdef3456789012cdef3456789012cdef3456789012cd","format":"cyclonedx","url":"https://provenance.aureliasrs.ca/sbom/sha256:img003456789.json"},"signingSystem":{"jurisdiction":"Canada","keyManagement":"hardware-security-module","type":"gpg"},"slsa":{"builderLevel":3,"invocation":{"configSource":{"digest":{"sha256":"7c6d5e4f3210fedcba0987654321fedcba098765"},"entryPoint":".github/workflows/docker-build.yaml","uri":"git+https://github.com/aureliasrs/api-service@refs/tags/v3.1.0"}},"level":3,"materials":[{"digest":{"sha256":"7c6d5e4f3210fedcba0987654321fedcba098765"},"uri":"git+https://github.com/aureliasrs/api-service@refs/tags/v3.1.0"}]}},"verification":{"attestationsVerified":true,"digestVerified":true,"lastVerifiedAt":"2026-01-16T06:00:00Z","signatureVerified":true,"verificationLog":"https://provenance.aureliasrs.ca/verification-logs/img003456789.txt","verificationMethod":"automated"}},"links":{"html":"/channels/container-images/releases/v3.1.0/sha256-img003456789012cdef3456789012cdef3456789012cdef3456789012cdef34/","release":"/channels/container-images/releases/v3.1.0/","channel":"/channels/container-images/releases/"}}