Images
The catalog covers three Bluefin image families: Bluefin, Bluefin Classic
(published by ublue-os), and Utah.
Bluefin
Bluefin stable and testing image streams.
Bluefin
Project Bluefin Dakota image stream built with BuildStream.
Last validated: Sep 29, 2026 · Last published: Sep 29, 2026 Graphics Drivers Add Nvidia driver? Use this command to switch to the stable channel for this image. It is the quickest way to stay on that release stream. Use this command to switch to the testing channel for this image. It is the quickest way to stay on that release stream. No published cosign key URL in this catalog. Signature verification confirms this image was signed by the expected maintainers and helps detect tampering before deployment. Learn more. Provenance attestation lets you validate how the image was built in CI so you can make trust decisions from evidence. Learn more. When present, SBOMs are published alongside images as OCI referrers. Use oras to inspect attached artifacts and pull the SBOM for audits, policy checks, and vulnerability triage. Learn more.Streams
Signing and SBOM
Bluefin Classic
Current Bluefin releases from ublue-os/bluefin.
Bluefin Classic
Primary Bluefin desktop image for most systems.
Last validated: Sep 29, 2026 · Last published: Sep 29, 2026 Graphics Drivers Add Nvidia driver? Use this command to switch to the stable channel for this image. It is the quickest way to stay on that release stream. Use this command to switch to the stable-daily channel for this image. It is the quickest way to stay on that release stream. Use this command to switch to the latest channel for this image. It is the quickest way to stay on that release stream. Key: Signature verification confirms this image was signed by the expected maintainers and helps detect tampering before deployment. Learn more. Note: key-based signature verification of legacy Provenance attestation lets you validate how the image was built in CI so you can make trust decisions from evidence. Learn more. When present, SBOMs are published alongside images as OCI referrers. Use oras to inspect attached artifacts and pull the SBOM for audits, policy checks, and vulnerability triage. Learn more.Streams
Signing and SBOM
https://raw.githubusercontent.com/ublue-os/bluefin/main/cosign.pub.sig tags requires cosign v2.x (cosign v3+ defaults to OCI 1.1 referrers). Use the Verify Provenance tab for keyless OIDC verification on cosign v3+.
Utah
Project Bluefin built with Fedora Hummingbird technology.
Project Bluefin Utah
Project Bluefin Utah image stream built with Fedora Hummingbird technology.
Last validated: Sep 29, 2026 · Last published: Sep 29, 2026 Graphics Drivers Add Nvidia driver? Use this command to switch to the testing channel for this image. It is the quickest way to stay on that release stream. No published cosign key URL in this catalog. Signature verification confirms this image was signed by the expected maintainers and helps detect tampering before deployment. Learn more. Provenance attestation lets you validate how the image was built in CI so you can make trust decisions from evidence. Learn more. Attestation verification command unavailable. When present, SBOMs are published alongside images as OCI referrers. Use oras to inspect attached artifacts and pull the SBOM for audits, policy checks, and vulnerability triage. Learn more.Streams
Signing and SBOM