Notation is a CLI project to add signatures as standard items in the OCI registry ecosystem, and to build a set of simple tooling for signing and verifying these signatures. This should be viewed as similar security to checking git commit signatures, although the signatures are generic and can be used for additional purposes. Notation is an implementation of the Notary Project specifications.
You can find the Notary Project README to learn about the overall Notary Project.
The documentation for installing Notation CLI is available here.
Table of Contents
- Quick Start
- Release Management
- Code of Conduct
- Quick start: Sign and validate a container image
- Try out Notation in this Killercoda interactive sandbox environment
- Build, sign, and verify container images using Notation with Azure Key Vault or AWS Signer
Notary Project is a CNCF Incubating project. We ❤️ your contribution.
Development and Contributing
- Build Notation from source code
- Governance for Notary Project
- Maintainers and reviewers list
- Regular conversations for Notary Project occur on the Cloud Native Computing Slack notary-project channel.
Notary Project Community Meeting
- Mondays 5-6 PM PDT, 4-5 PM PST, 8-9 PM EDT, 7-8 PM EST, 8-9 AM Shanghai
- Thursdays 9-10 AM PDT, 8-9 AM PST, 12 PM EDT, 11 AM EST, 5 PM UK
The Notation release process is defined in RELEASE_MANAGEMENT.md.
Support for the Notation project is defined in supported releases.
Code of Conduct
This project is covered under the Apache 2.0 license. You can read the license here.