SECOND MEASUREMENT SM-007

Docker promised signed attestations for every Official Image. The attestations arrived; the signatures didn't

Markovian ProtocolMeasured 2026-10-02Status: sent to Docker 2026-10-02, response pendingDOI: 10.5281/zenodo.23122993

Docker Official Images are the most-pulled containers on the internet: nginx, python, postgres, alpine. In April 2024 Docker said it was committed to shipping signed SBOMs and build provenance for all of them. We checked every one. The attestations are there on 7,368 of 7,372 Linux images. Not one of the 45 we sampled is signed. Docker's older signing service shuts down on 8 December, and the replacement it announced in July 2025 hasn't appeared.

8 Decis when Docker’s old signing service, notary.docker.io, shuts down. Official Images have no signatures to replace it yet.
The short version

Disclosure: Markovian Protocol holds no financial position in any organisation named here, was paid by no one for this work, and showed it to no one before publication except the organisation measured. How we work.

Details

An attestation is a statement attached to an image saying what is inside it (an SBOM, the ingredient list) and how it was built (provenance). Signed, it lets anyone check the statement came from Docker’s build system and wasn’t changed afterwards. Unsigned, it is a note anyone who can push to the repository could rewrite. Docker’s attestations are in-toto statements stored next to each image; a signed one would be wrapped in a DSSE envelope or have a signature attached through the registry.

What they said, what we found

Docker saidWe found
“We are committed to providing a complete and accurate SBOM and detailed build provenance as signed attestations for all Docker Official Images.” (April 2024)1Complete: 7,368 of 7,372 Linux platform images carry an attestation manifest; of 45 opened, 37 carry both SBOM and provenance. Signed: 0 of 45 repositories sampled.
“in the near future, will be implementing a different image signing solution for DOI” (July 2025)2Fourteen months on, no new signing appears on any image we checked.
“The Notary v1 service at notary.docker.io will shut down on December 8, 2026.”3After that date, Official Images have no working signature of any kind until the replacement ships.

The paper trail

WhenWhat Docker published
Oct 2023A plan to sign Official Images with OpenPubkey. In passing, it calls the provenance Docker already ships “the unsigned provenance attestations that the Docker build process generates”.4
Apr 2024The commitment: signed SBOM and provenance “for all Docker Official Images”.1
Jul 2025Docker Content Trust, the old way of signing image tags, is retired for Official Images; certificates start expiring 8 August 2025. A replacement is coming “in the near future”. “Watch this blog for more information.”2
SinceThe signing library built for the job, docker/attest, now sits archived under docker-archive-public.5 The Official Images blog tag has no post after January 2025.6
8 Dec 2026The old signing service shuts down.3

Counting every image

The list of Official Images lives in a public repository, one file per image with every supported tag and architecture.7 We took all 2,086 image entries across 137 repositories and asked Docker Hub what each one contains. Attestations show up there as extra entries next to each platform build.

EntriesPlatform imagesWith attestations
Linux1,9477,3727,368
Windows1391390

Docker Hub, 2 October 2026, at official-images commit d74324e. The four Linux gaps are one platform each on four busybox tags.

On Linux the build side of the promise is close to done. The Windows images, across 15 repositories including python, golang and mongo, carry none.

Looking for a signature

A signature could live in three places, and we checked them on a random sample of repositories: inside the attestation itself, as a cosign signature tag beside the image, and through the registry’s referrers API, which lists anything attached to an image.

Where a signature would beFound
Attestation wrapped in a signed DSSE envelope0 of 45
Cosign .sig or .att tag0 of 10 checked
Anything attached through the referrers API0 of 45

Every attestation we read is a plain in-toto statement, media type application/vnd.in-toto+json, SPDX for the SBOM and SLSA v0.2 for provenance. They describe the image accurately as far as we can tell. Nothing proves Docker wrote them.

How this ends

It ends when a Docker Official Image’s attestation carries a signature anyone can verify: a DSSE envelope, a referrer in the registry, or a Sigstore entry. The weekly recheck probes the same images and will show the first signed one. The other ending is the calendar: on 8 December 2026 the old Notary signatures stop, and “unsigned” becomes the only state there is.

The evidence

Every quote below was copied from the source and checked against a saved copy, fetched 2026-10-02T17:51:35Z. The copies and their SHA-256 hashes are published next to this page (SHA256SUMS).

Exhibit 1 · The promise, April 2024

“We are committed to providing a complete and accurate SBOM and detailed build provenance as signed attestations for all Docker Official Images.”

docker.com/blog/enhancing-security-and-transparency-with-docker-official-images · saved copy docker-blog-2024-04.html

Exhibit 2 · Docker on its own provenance, October 2023

“…are already included in the unsigned provenance attestations that the Docker build process generates.”

docker.com/blog/signing-docker-official-images-using-openpubkey · saved copy docker-blog-2023-10.html

Exhibit 3 · The replacement, July 2025

“Docker is committed to improving the trust of the container ecosystem and, in the near future, will be implementing a different image signing solution for DOI… Watch this blog for more information.”

docker.com/blog/retiring-docker-content-trust · saved copy docker-blog-2025-07.html

Exhibit 4 · The deadline

“The Notary v1 service at notary.docker.io will shut down on December 8, 2026.”

docs.docker.com/engine/security/trust · saved copy docker-docs-trust.html

Exhibit 5 · nginx:latest, the attestation itself

"layers": [
  { "mediaType": "application/vnd.in-toto+json",
    "annotations": { "in-toto.io/predicate-type": "https://spdx.dev/Document" } },
  { "mediaType": "application/vnd.in-toto+json",
    "annotations": { "in-toto.io/predicate-type": "https://slsa.dev/provenance/v0.2" } } ]

A plain statement. A signed one would be a DSSE envelope.

registry-1.docker.io/v2/library/nginx/manifests/<attestation digest> · raw nginx-latest-attestation-manifest.json

Exhibit 6 · nginx:latest, everything attached to it

{"schemaVersion":2,"mediaType":"application/vnd.oci.image.index.v1+json","manifests":[]}

registry-1.docker.io/v2/library/nginx/referrers/sha256:abe47724…199f8cf2 · raw nginx-latest-referrers.json

Our questions to Docker

Sent to Docker by email on 2 October 2026. Answers will be printed here as written.

  1. Are Docker Official Images’ attestations signed through any channel we didn’t check? If so, where?
  2. Does the April 2024 commitment to “signed attestations for all Docker Official Images” still stand?
  3. When will the signing solution announced in July 2025 ship?
  4. Will it sign the existing SBOM and provenance attestations, the images, or both?
  5. What should users who verify signatures do between 8 December 2026 and that date?
  6. Will the Windows Official Images get attestations?
  7. Is the archived docker/attest library still the planned signing path?

Their reply, scored

Waiting for a reply. When it comes, each question gets marked answered, partly answered or not answered, and the reply goes here in full.

Disclosure timeline

2 OctPublished; sent to Docker’s security team.
2 OctSeven numbered questions sent.
8 DecDocker’s old signing service shuts down.

Waiting on Docker since 2 Oct.

What we can’t be sure of

Run it yourself

Python 3 standard library. Docker Hub’s registry allows 100 anonymous manifest reads an hour, so the signing check is paced.

git clone --depth 1 https://github.com/docker-library/official-images oi
python3 census2.py     # every image entry: platforms vs attestations (Hub tag API)
python3 signing.py 50  # 50 random repos: attestation media type and referrers
python3 probe.py nginx:latest python:3.13   # one image in detail

Reproduced from the public repository on 3 October 2026 on a clean machine: the probe holds (attestations present, no signature media type). The full census takes about 25 minutes and the signing sample depends on it. Full table on the track record.

What you can do with this

References

  1. Docker. From Misconceptions to Mastery: Enhancing Security and Transparency with Docker Official Images. 4 April 2024. docker.com/blog.
  2. Docker. Retiring Docker Content Trust. 29 July 2025. docker.com/blog.
  3. Docker. Content trust in Docker (documentation). docs.docker.com/engine/security/trust, read 2 October 2026.
  4. Docker. Signing Docker Official Images Using OpenPubkey. 13 October 2023. docker.com/blog.
  5. github.com/docker-archive-public/docker.attest (archived).
  6. Docker blog, tag “Docker Official Images”, docker.com/blog/tag/docker-official-images, read 2 October 2026.
  7. github.com/docker-library/official-images, commit d74324e.
  8. Docker. Docker Official Images (documentation). docs.docker.com/trusted-content/official-images.

Cite as

@misc{markovian-sm007,
  author = {{Markovian Protocol}},
  title  = {Docker Official Images: attestations present, signatures absent},
  number = {SM-007},
  doi    = {10.5281/zenodo.23122993},
  year   = {2026},
  month  = oct,
  url    = {https://markovianprotocol.com/measurements/sm-007.html}
}