Manufacturers who ship container images already have the facts a regulator will ask for. BuildKit, the engine behind docker build, writes the image digest to a metadata file at build time, attaches a SLSA provenance attestation that names the source commit and the base images, and can attach a software bill of materials (SBOM) to the image. Until now, freezing a release in Vibgrate Evidence meant copying those values into a command by hand, which is slow and easy to get wrong.
The Vibgrate CLI now reads them directly. vg evidence release accepts the BuildKit metadata file for the image digest and build reference, a provenance attestation for the source repository, commit, and base images, and an SPDX or CycloneDX SBOM, bare or wrapped in an in-toto attestation, for the component list. With a Docker daemon available, a single --image flag reads all of that from the image and its attached attestations.
The result is a frozen release manifest tied to the artefact that actually shipped. The manifest records where each fact came from, and two rules keep it honest: a digest typed by hand that disagrees with what the build wrote is an error, not a silent preference, and attestation signatures are recorded as unverified because the CLI carries no registry trust root. Teams verify signatures with cosign; Vibgrate records what it read.
In the same release, the Vibgrate CLI's code graph now records Dockerfile LABEL instructions, so org.opencontainers.image.source, revision, and related labels appear as facts on the build stage that declares them.
Vibgrate Evidence produces evidence to support reporting obligations. It does not determine compliance, is not a certification, and is not legal advice.
The change ships in the Vibgrate CLI, free and open source under Apache 2.0.