Skip to main content
Press release

Vibgrate Evidence freezes container releases from BuildKit build outputs

The Vibgrate CLI now reads the image digest, source commit, base images, and SBOM that BuildKit already wrote, so a frozen release manifest is tied to the container image that shipped rather than to values typed in by hand.

Manufacturers who ship container images already have the facts a regulator will ask for. BuildKit, the engine behind docker build, writes the image digest to a metadata file at build time, attaches a SLSA provenance attestation that names the source commit and the base images, and can attach a software bill of materials (SBOM) to the image. Until now, freezing a release in Vibgrate Evidence meant copying those values into a command by hand, which is slow and easy to get wrong.

The Vibgrate CLI now reads them directly. vg evidence release accepts the BuildKit metadata file for the image digest and build reference, a provenance attestation for the source repository, commit, and base images, and an SPDX or CycloneDX SBOM, bare or wrapped in an in-toto attestation, for the component list. With a Docker daemon available, a single --image flag reads all of that from the image and its attached attestations.

The result is a frozen release manifest tied to the artefact that actually shipped. The manifest records where each fact came from, and two rules keep it honest: a digest typed by hand that disagrees with what the build wrote is an error, not a silent preference, and attestation signatures are recorded as unverified because the CLI carries no registry trust root. Teams verify signatures with cosign; Vibgrate records what it read.

In the same release, the Vibgrate CLI's code graph now records Dockerfile LABEL instructions, so org.opencontainers.image.source, revision, and related labels appear as facts on the build stage that declares them.

Vibgrate Evidence produces evidence to support reporting obligations. It does not determine compliance, is not a certification, and is not legal advice.

The change ships in the Vibgrate CLI, free and open source under Apache 2.0.

“The build already knows what it produced. Asking a release manager to retype the digest and the commit was where the record could drift from the artefact. Now the manifest reads what BuildKit wrote, and says plainly what it did and did not verify.”
Peter Chapman — Founder, Vibgrate

Facts and primary sources

  • BuildKit can attach SLSA provenance and SBOM attestations to an image at build time, and BuildKit is the default builder for Docker Engine and Docker Desktop since version 23.0. Read Docker's build attestations documentation
  • SLSA provenance is an in-toto attestation that describes how an artifact was produced, including the builder, the source, and the materials that went into the build. Read the SLSA provenance specification

About Vibgrate

Vibgrate is a software intelligence platform that helps teams find aging dependencies, assess security exposure, and plan modernization. Its free CLI maps codebases and produces DriftScore, a transparent measure of dependency, framework, and runtime drift. Vibgrate Cloud adds portfolio visibility, governance workflows, and verifiable evidence for security and regulatory decisions. Vibgrate Evidence preserves version-specific component and release records so teams can reproduce historical exposure findings. Vibgrate AI Context gives coding agents version-matched documentation and precise repository context while reducing unnecessary token use. Vibgrate publishes its scoring methodology openly, allowing researchers to inspect the evidence, assumptions, and formulas behind its results.

25-word boilerplate

Vibgrate helps software teams find aging dependencies, assess security exposure, and plan modernization using verifiable evidence produced by its free code-scanning CLI and cloud platform.

50-word boilerplate

Vibgrate is a code drift intelligence platform for software teams. Its free CLI maps a codebase and identifies drift across dependencies, frameworks, and runtimes. Vibgrate Cloud turns the same scan data into portfolio visibility, governance workflows, security prioritization, and verifiable evidence for modernization decisions, regulatory reporting, and ongoing software assurance.

Press inquiries

Peter Chapman, Founder · press@vibgrate.com