Clearcutt Catalog
Reference Catalog

Clearcutt Catalog

Use this catalog to containerize applications with approved runtime images, inspect evidence, and find the next step for your role.

This reference site renders the upstream catalog for northcutted/clearcutt from ghcr.io/northcutted/clearcutt. ClearCutt provides the renderer and workflow kit; fork owners control their catalog and evidence.

Catalog snapshot v0.14.0
Generated
8/3/2026, 7:26:24 AM
Registry
ghcr.io/northcutted/clearcutt
Source
northcutted/clearcutt
Generator
ClearCutt static portal

Start Here

Pick the next action instead of reading the site in order.

4 paths

Workflows By Role

Each path points to existing catalog pages and commands, so the generated site stays useful after branding changes.

Fleet operations

Platform engineers

Publish, govern, and maintain the approved image fleet.

  1. 1

    Check catalog coverage

    Confirm latest images, pending matrix slots, services, and evidence counts.

    Open matrix
  2. 2

    Fork and configure the fleet

    Review the platform kit commands, fleet config contract, and generated site workflow.

    Open platform kit
  3. 3

    Publish refreshed catalog data

    Generate catalog data and build the static site artifact for your own registry.

    clearcutt catalog site build --catalog ./dist/catalog --output ./dist/site --install
App delivery

Application engineers

Pick a runtime image, build an app container, and validate it before release.

  1. 1

    Choose a runtime and tier

    Use the catalog matrix to find the right language version and production tier.

    Choose an image
  2. 2

    Copy the build pattern

    Start with a dev-to-runtime multi-stage example that does not require Nix locally.

    Copy app pattern
  3. 3

    Plan rebase and certification

    Use app lifecycle examples for app build, diff-base, certify, and rebase workflows.

    Open lifecycle
Evidence review

Security and audit engineers

Review evidence channels, vulnerability state, and threat-model boundaries.

  1. 1

    Verify supply-chain evidence

    Run the audit guide checks for keyless signatures, SLSA provenance, and SBOMs.

    Verify evidence
  2. 2

    Inspect vulnerabilities

    Use image detail pages to review active findings, fix state, OpenVEX notes, and exceptions.

    Inspect findings
  3. 3

    Read the boundaries

    Confirm what shell-free, provenance, and remediation claims do and do not prove.

    Read limits

Current State

Factual catalog counts only; inspect image detail pages before containerizing an app for production.

View matrix
Current runtimes
39/52

13 pending matrix slots

Release
v0.14.0

published 7/11/2026

Signatures
39/39

39/39 provenance · 39/39 scans

Services
3

service image records

Tier Reminder

Dev images are for build stages. Production workloads should use Distroless or a diagnostic runtime tier after reviewing the image detail page.

Evidence Reminder

Signatures, provenance, SBOMs, vulnerability scans, test results, and release metadata are reported independently.

Customization

Generated-site owners can change this homepage through site.home in clearcutt.site.yaml, or replace pages with site-overrides.