👏🎉We’re excited to announce that Ratify has officially joined the Notary Project as a subproject after the vote passed in the community! This marks a significant step forward in our shared mission to deliver secure and trusted software supply chain
notaryproject.dev/blog/2025/…
If you want to get a quick overview of #NotaryProject and how you can use it to sign container images and other arbitrary files, the lightning talk from @yizha1bell #KubeCon is a great start. Find us on Notary Project kiosk and maintainers track at KubeCon EU this week!
Check out two latest episodes from @jrrickardand @toddysmto to learn how to use @NotaryProject to sign container images and ensure image integrity in production: techcommunity.microsoft.com/…
Glad to collaborate with @project_harbor to integrate Notation into Harbor UI. By leveraging the OCI Referrers API, the Notary Project signature is naturally supported by the Harbor registry now.
🎉We Just released Harbor 2.9 which has great new features such as Security Hub - able to view all your CVEs at a glance or to be able to set up a notification banner, integration with #notation from @NotaryProject, and many more. Check the full list here: goharbor.io/blog/harbor-2.9/
We have maintainers @toddysm@justincormack who are ready to see everyone at #KubeConEU. They will bring the session Securing the Container Supply Chain with Notary on Apr 21! sched.co/1HyUS@sched You will know what's new in the Notary project and how it works now.
Please join #KubeConEU 2023 for the session Improve Vulnerability Management with OCI Artifacts – It Is That Easy! with @itaysk@toddysmsched.co/1Hyat@sched You will learn how to improve vulnerability management practices using new registry capabilities and OSS tools.
✨It's nice to see @containerd nerdctl integrates Notation to implement image signing and verification. Credits to our new contributor @ningziwen who drives this work across two communities.
➡️Check out this doc to sign and verify image with nerdctl: github.com/containerd/nerdct…
Notation is a tool to sign, store, and verify artifacts. It aims to safeguard the software supply chain security. We are pleased to release v1.0.0-RC.1 for the CLI and library. Try it now by following the quick start:
notaryproject.dev/docs/quick…