Architecture
The English user guide is currently in beta preview. Most of the documents have been automatically translated from the Japanese version. Should you find any inaccuracies, please reach out to Flatt Security.
Every image in the catalog is built and published through the same pipeline.
Build Pipeline Overview explains the path from pinned Nix expressions through hermetic builds, tests, signatures, and attestations. Known Vulnerability Response explains the three paths by which known vulnerabilities leave an image: following upstream releases, applying package-level patches, and recording decisions in VEX. Upstream Malware Detection explains how Takumi Images continuously monitors upstream sources for signs of malicious changes. Upstream Zero-Day Fix Detection explains how the same monitoring can identify signs of silent security fixes before a vulnerability ID is published.
The build pipeline and known-vulnerability response leave verifiable evidence through SBOMs, VEX, and provenance.