“Can you confirm that our production container images have valid SBOMs, signatures, and attestations?”
Should have been routine. Quick check, thumbs up, move on. Instead I spent the next hour copying digests between terminal windows, mentally mapping relationships between image indexes and their referrers, and wondering why verifying a container’s supply chain felt like archaeology.
So I built OCI Image Explorer – an open-source tool that shows everything attached to a container image in one view. Try it at ociexplorer.dev.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.