Trust center
Supply chain
Signed images, a software bill of materials for every release, and how to verify them offline.
Every release image is built in CI, scanned, and signed before you download it.
| Control | Status | Detail |
|---|---|---|
| Signed images | In place | Sigstore keyless signing (Cosign) from the CI pipeline; no long-lived signing key to steal |
| SBOM | In place | SPDX JSON software bill of materials, generated by Syft, for every image |
| Vulnerability gate | In place | Grype scan fails the build on any High or Critical finding |
| Pinned base image | In place | Base image pinned by SHA-256 digest |
| Checksums | In place | SHA-256 for every download |
| VEX statements | Planned | Exploitability notes for CVEs reported in dependencies that do not affect the product |
Verify before you import
Check the signature and digest on a connected machine, then carry the verified tarball into the air gap. The verification guide has the exact commands.
Dependencies
Fonts and libraries are bundled into the image. The app makes no runtime requests to package registries or CDNs.
Last updated 2026-10-01.