The Open Component Model (OCM) is your one-stop open-source
Software Bill of Delivery (SBoD)
for packaging, signing, transporting and deploying your artifacts β preserving end-to-end security, integrity and provenance.
Get StartedDefine components in code with powerful lifecycle metadata.
Add cryptographic signatures. End-to-end trust from source to deployment.
Works across boundaries β public cloud, on-prem, air-gapped. Tamper-proof.
Automate deployments with OCM controllers and Flux. Seamless GitOps.
Gain visibility into everything you deliver β from container images to configuration files.
Secure the integrity and provenance of your software with built-in signing and verification.
Deliver across any system or environment without loosing traceability.
OCM fits seamlessly into your current ecosystem and workflows.
OCM's functionality is easy to extend. Just plug in what you need.
We champion open innovation β in OCM and across the community.