Open source · Cloud & Platform

Container Image Provenance Checker

Check an exported OCI manifest digest and signed claims against an offline trust policy.

v0.1.0 · Node.js 22+ · MIT

Browse the public repository · View releases

Offline, read-only check of an exported OCI image manifest against a caller-supplied expected SHA-256 digest and an Ed25519-signed provenance bundle. It never contacts a registry, pulls an image, discovers trust roots, or signs anything. The trust policy must contain the public keys the operator already trusts. A signature over the wrong digest, source commit, or builder is not a pass.

This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.

Run the checked-in example

node bin/container-image-provenance-checker.mjs --root examples --policy policy.json --manifest manifest.json --bundle bundle.json
node bin/container-image-provenance-checker.mjs --root examples --policy failing-policy.json --manifest manifest.json --bundle bundle.json

Read the result

The first command exits 0; the second exits 1 with artifact-digest-mismatch. Fixtures use synthetic source identifiers and a public-only test key. The private fixture signing key was ephemeral and is not packaged.

Where this check stops

This local walkthrough does not establish the state of a live production system or replace the limits documented in the repository.

Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.

Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.