Releases: edilec/container-image-provenance-checker
Release list
Container Image Provenance Checker v0.1.0
Container Image Provenance Checker v0.1.0
Public MIT source release of Edilec's offline, read-only OCI manifest and signed-bundle checker. Given local files, it compares the SHA-256 digest of the exact exported manifest bytes with a caller-supplied expected digest and verifies Ed25519-signed claims against a caller-supplied trust policy. It also checks the expected source commit and allowed builder. Reports distinguish pass, policy failure and incomplete evidence. The repository includes synthetic passing and failing examples.
Run the checked-in examples with Node.js 22 or newer as shown in the README. This is a GitHub source release; the package has not been published to npm.
The checker does not contact a registry, inspect image layers, discover trust roots, validate SLSA/in-toto statements or enforce deployment admission. Operators must establish their policy keys and expected values independently. For the broader delivery workflow, see Edilec's build provenance guide.
Maintained by Edilec. These release notes were drafted with AI assistance and checked against the public repository, examples and test results.