Clearcutt Catalog
Reference Catalog
Image selection

Pick a runtime image.

Use the matrix to compare runtime, tier, release state, service images, and attached evidence before you containerize or admit an application.

CVE counts on the catalog are refreshed nightly against current vulnerability advisories, so a stable SBOM picks up newly-disclosed issues without a new release. Each image page explains fix state and evidence. Dev images include full toolchains and must not be deployed.

39 on v0.14.0 13 pending of 52 target slots services: 3 evidence: 39/39 sig · 39/39 slsa · 39/39 scans

Evidence & Policy Legend

Supply Chain Evidence

Green icons indicate evidence present in the catalog for the OCI manifest: Sigstore keyless OIDC signature, SLSA Build L3 provenance, and SPDX SBOM. Use the audit guide to verify it locally.

The generated evidence-manifest.json indexes each release's expected, observed, and missing evidence channels.

Download evidence manifest

No high/critical in current scan Current Scan Results

Images show No high/critical in current scan when attached scan data reports no active Critical or High findings. Counts of outstanding CVE findings display in red (critical) or orange (high) badges.

SHELL-FREE EVIDENCE LISTED

Shell-Free indicates that shells, core utilities, and package managers are omitted from the runtime. Evidence Listed means the catalog exposes signatures, SBOMs, provenance, and workflow identities separately.

View: Filters are stacked: each adds to the selection above.
GNU Bash

Core

1 version / 3/3 current

LTS
OpenJDK

Java

2 versions / 3/3 current

25
Node.js

Node.js

2 versions / 3/3 current

24
Python

Python

2 versions / 3/3 current

3.14
Go

Go

2 versions / 3/3 current

1.26
.NET

.NET

2 versions / 3/3 current

10
Rust

Rust

1 version / 3/3 current

1.95
C/C++

C/C++

1 version / 3/3 current

15

Service Images

Platform-owned application services built from Nix package templates, cataloged separately from runtime tiers.

3 services
postgres16
postgres16
non-prod
Lifecyclepreview
Portspostgres:5432/tcp
Storage/var/lib/postgresql/data
Vulnerabilities1 critical / 9 high
Open service image
valkey8
valkey8
non-prod
Lifecyclepreview
Portsredis:6379/tcp
Storage/data
Vulnerabilities2 critical / 16 high
Open service image
oauth2-proxy7
oauth2-proxy7
non-prod
Lifecyclepreview
Portshttp:4180/tcp
Storagestateless
Vulnerabilities7 critical / 12 high
Open service image