By default only minimal provenance is attached and only for images pushed to a registry.
Verify attestations after push with docker buildx imagetools inspect --format '{{json .SBOM}}' or '{{json .Provenance}}' for the target registry reference, and {{json .}} for the full structure.
Official docs: https://docs.docker.com/reference/cli/docker/buildx/build/ ; https://docs.docker.com/reference/cli/docker/buildx/imagetools/inspect/
Known gotchas
The default Docker Engine image store does not support attestations — you must use the containerd image store or push directly to the registry, otherwise attestations are not produced.
Attestations are attached at export; a local --load build typically won't carry SBOM/provenance artifacts.
inspect --format with the json template function (e.g. {{json .SBOM}}) is how you read them back — the plain .SBOM field alone may print a memory address-style placeholder.
Give your agent this knowledge — and 17,200+ more routes
One MCP install gives any agent live access to the full route map across 5,900+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?