SECOND MEASUREMENT SM-007
Docker promised signed attestations for every Official Image. The attestations arrived; the signatures didn't
Docker Official Images are the most-pulled containers on the internet: nginx, python, postgres, alpine. In April 2024 Docker said it was committed to shipping signed SBOMs and build provenance for all of them. We checked every one. The attestations are there on 7,368 of 7,372 Linux images. Not one of the 45 we sampled is signed. Docker's older signing service shuts down on 8 December, and the replacement it announced in July 2025 hasn't appeared.
- Docker committed in April 2024 to signed SBOM and provenance attestations for all Official Images.
- The attestations exist: 7,368 of 7,372 Linux images (99.9%) across 137 repositories carry an attestation manifest; of the 45 we opened, 37 hold both an SBOM and provenance, 7 provenance only, 1 SBOM only.
- None are signed: 0 of 45 sampled repositories have a signature anywhere we looked.
- The 139 Windows images, across 15 repositories, carry no attestations at all.
- Docker’s old signing service shuts down on 8 December 2026. The replacement it announced in July 2025 hasn’t appeared.
Disclosure: Markovian Protocol holds no financial position in any organisation named here, was paid by no one for this work, and showed it to no one before publication except the organisation measured. How we work.
An attestation is a statement attached to an image saying what is inside it (an SBOM, the ingredient list) and how it was built (provenance). Signed, it lets anyone check the statement came from Docker’s build system and wasn’t changed afterwards. Unsigned, it is a note anyone who can push to the repository could rewrite. Docker’s attestations are in-toto statements stored next to each image; a signed one would be wrapped in a DSSE envelope or have a signature attached through the registry.
What they said, what we found
| Docker said | We found |
|---|---|
| “We are committed to providing a complete and accurate SBOM and detailed build provenance as signed attestations for all Docker Official Images.” (April 2024)1 | Complete: 7,368 of 7,372 Linux platform images carry an attestation manifest; of 45 opened, 37 carry both SBOM and provenance. Signed: 0 of 45 repositories sampled. |
| “in the near future, will be implementing a different image signing solution for DOI” (July 2025)2 | Fourteen months on, no new signing appears on any image we checked. |
| “The Notary v1 service at notary.docker.io will shut down on December 8, 2026.”3 | After that date, Official Images have no working signature of any kind until the replacement ships. |
The paper trail
| When | What Docker published |
|---|---|
| Oct 2023 | A plan to sign Official Images with OpenPubkey. In passing, it calls the provenance Docker already ships “the unsigned provenance attestations that the Docker build process generates”.4 |
| Apr 2024 | The commitment: signed SBOM and provenance “for all Docker Official Images”.1 |
| Jul 2025 | Docker Content Trust, the old way of signing image tags, is retired for Official Images; certificates start expiring 8 August 2025. A replacement is coming “in the near future”. “Watch this blog for more information.”2 |
| Since | The signing library built for the job, docker/attest, now sits archived under docker-archive-public.5 The Official Images blog tag has no post after January 2025.6 |
| 8 Dec 2026 | The old signing service shuts down.3 |
Counting every image
The list of Official Images lives in a public repository, one file per image with every supported tag and architecture.7 We took all 2,086 image entries across 137 repositories and asked Docker Hub what each one contains. Attestations show up there as extra entries next to each platform build.
| Entries | Platform images | With attestations | |
|---|---|---|---|
| Linux | 1,947 | 7,372 | 7,368 |
| Windows | 139 | 139 | 0 |
Docker Hub, 2 October 2026, at official-images commit d74324e. The four Linux gaps are one platform each on four busybox tags.
On Linux the build side of the promise is close to done. The Windows images, across 15 repositories including python, golang and mongo, carry none.
Looking for a signature
A signature could live in three places, and we checked them on a random sample of repositories: inside the attestation itself, as a cosign signature tag beside the image, and through the registry’s referrers API, which lists anything attached to an image.
| Where a signature would be | Found |
|---|---|
| Attestation wrapped in a signed DSSE envelope | 0 of 45 |
Cosign .sig or .att tag | 0 of 10 checked |
| Anything attached through the referrers API | 0 of 45 |
Every attestation we read is a plain in-toto statement, media type application/vnd.in-toto+json, SPDX for the SBOM and SLSA v0.2 for provenance. They describe the image accurately as far as we can tell. Nothing proves Docker wrote them.
How this ends
It ends when a Docker Official Image’s attestation carries a signature anyone can verify: a DSSE envelope, a referrer in the registry, or a Sigstore entry. The weekly recheck probes the same images and will show the first signed one. The other ending is the calendar: on 8 December 2026 the old Notary signatures stop, and “unsigned” becomes the only state there is.
The evidence
Every quote below was copied from the source and checked against a saved copy, fetched 2026-10-02T17:51:35Z. The copies and their SHA-256 hashes are published next to this page (SHA256SUMS).
Exhibit 1 · The promise, April 2024
“We are committed to providing a complete and accurate SBOM and detailed build provenance as signed attestations for all Docker Official Images.”
docker.com/blog/enhancing-security-and-transparency-with-docker-official-images · saved copy docker-blog-2024-04.html
Exhibit 2 · Docker on its own provenance, October 2023
“…are already included in the unsigned provenance attestations that the Docker build process generates.”
docker.com/blog/signing-docker-official-images-using-openpubkey · saved copy docker-blog-2023-10.html
Exhibit 3 · The replacement, July 2025
“Docker is committed to improving the trust of the container ecosystem and, in the near future, will be implementing a different image signing solution for DOI… Watch this blog for more information.”
docker.com/blog/retiring-docker-content-trust · saved copy docker-blog-2025-07.html
Exhibit 4 · The deadline
“The Notary v1 service at notary.docker.io will shut down on December 8, 2026.”
docs.docker.com/engine/security/trust · saved copy docker-docs-trust.html
Exhibit 5 · nginx:latest, the attestation itself
"layers": [
{ "mediaType": "application/vnd.in-toto+json",
"annotations": { "in-toto.io/predicate-type": "https://spdx.dev/Document" } },
{ "mediaType": "application/vnd.in-toto+json",
"annotations": { "in-toto.io/predicate-type": "https://slsa.dev/provenance/v0.2" } } ]A plain statement. A signed one would be a DSSE envelope.
registry-1.docker.io/v2/library/nginx/manifests/<attestation digest> · raw nginx-latest-attestation-manifest.json
Exhibit 6 · nginx:latest, everything attached to it
{"schemaVersion":2,"mediaType":"application/vnd.oci.image.index.v1+json","manifests":[]}registry-1.docker.io/v2/library/nginx/referrers/sha256:abe47724…199f8cf2 · raw nginx-latest-referrers.json
Our questions to Docker
Sent to Docker by email on 2 October 2026. Answers will be printed here as written.
- Are Docker Official Images’ attestations signed through any channel we didn’t check? If so, where?
- Does the April 2024 commitment to “signed attestations for all Docker Official Images” still stand?
- When will the signing solution announced in July 2025 ship?
- Will it sign the existing SBOM and provenance attestations, the images, or both?
- What should users who verify signatures do between 8 December 2026 and that date?
- Will the Windows Official Images get attestations?
- Is the archived
docker/attestlibrary still the planned signing path?
Their reply, scored
Disclosure timeline
| 2 Oct | Published; sent to Docker’s security team. |
| 2 Oct | Seven numbered questions sent. |
| 8 Dec | Docker’s old signing service shuts down. |
Waiting on Docker since 2 Oct.
What we can’t be sure of
- Signing was checked on a random 45 of 137 repositories, one tag each. Coverage was checked on every entry.
- Docker could sign through a channel we didn’t look at. We checked the places its own tools and the OCI standard use.
- Docker says its separate Hardened Images product ships signed SBOM and provenance.8 We didn’t test that; it is a different set of images.
- An unsigned attestation isn’t a wrong one. The gap is that nobody outside Docker can prove it isn’t.
Run it yourself
Python 3 standard library. Docker Hub’s registry allows 100 anonymous manifest reads an hour, so the signing check is paced.
git clone --depth 1 https://github.com/docker-library/official-images oi python3 census2.py # every image entry: platforms vs attestations (Hub tag API) python3 signing.py 50 # 50 random repos: attestation media type and referrers python3 probe.py nginx:latest python:3.13 # one image in detail
Reproduced from the public repository on 3 October 2026 on a clean machine: the probe holds (attestations present, no signature media type). The full census takes about 25 minutes and the signing sample depends on it. Full table on the track record.
What you can do with this
- If you verify Docker Official Images, the attestations are there but unsigned; treat them as Docker's word, not as a signature, until the signing lands.
- If you pin to Notary v1 signatures, they stop on 8 December 2026.
References
- Docker. From Misconceptions to Mastery: Enhancing Security and Transparency with Docker Official Images. 4 April 2024. docker.com/blog.
- Docker. Retiring Docker Content Trust. 29 July 2025. docker.com/blog.
- Docker. Content trust in Docker (documentation). docs.docker.com/engine/security/trust, read 2 October 2026.
- Docker. Signing Docker Official Images Using OpenPubkey. 13 October 2023. docker.com/blog.
- github.com/docker-archive-public/docker.attest (archived).
- Docker blog, tag “Docker Official Images”, docker.com/blog/tag/docker-official-images, read 2 October 2026.
- github.com/docker-library/official-images, commit d74324e.
- Docker. Docker Official Images (documentation). docs.docker.com/trusted-content/official-images.
Cite as
@misc{markovian-sm007,
author = {{Markovian Protocol}},
title = {Docker Official Images: attestations present, signatures absent},
number = {SM-007},
doi = {10.5281/zenodo.23122993},
year = {2026},
month = oct,
url = {https://markovianprotocol.com/measurements/sm-007.html}
}