Skip to main content
Menu

Why Rasid

Five reasons to build on us instead of the upstream image or a closed hardened-image vendor.

Apache 2.0 binaries

Free pulls, free redistribution, NOTICE attribution preserved. Pull the binary, vendor the digest, redistribute under your own brand if you need to — that's what the licence is for.

Zero-CVE baseline

Daily rebuilds, advisory-driven patching, and a public scoreboard. Patch latency is the product.

Signed + attested

Cosign signatures and SLSA Level 3 in-toto provenance on every image. You can prove what you're running and what built it.

Self-hosted signing chain

Fulcio + Rekor at fulcio.rasid.cc + rekor.rasid.cc, verification key at /.well-known/rasid-cosign.pub. Verification touches only Rasid-operated infrastructure.

Engineered for production

Same interface as the upstream image — drop in a Dockerfile, in Kubernetes, in Compose, in a CI job. No retraining, no migration cost.