description Notation Overview
Notation is an open-source signing and verification tool from the Notary Project, designed for OCI artifacts such as container images and other registry-managed packages. It applies digital signatures and lets organizations verify those signatures against trust policies before accepting an artifact for use. Notation is aimed at developers, platform teams, registry operators, and security teams that need to protect software supply chains from unauthorized or altered artifacts. It addresses artifact identity and integrity, not operating-system resource allocation or container density.
help Notation FAQ
What is Notation used for?
Notation is an open-source tool from the Notary Project for signing and verifying OCI artifacts. Those artifacts can include container images and other packages stored in registries.
How does Notation verify a container image?
Notation checks a signature attached to an OCI artifact and evaluates it against configured trust policies. This lets an organization decide whether an image came from an approved signer before deployment.
Is Notation the same as Docker Content Trust?
No. Docker Content Trust is associated with Docker's older Notary v1 workflow, while Notation is built around the newer Notary Project and OCI artifact signing model. They use different tooling and trust workflows.
Where can Notation signatures be stored?
Notation is designed to work with OCI-compatible registries that can store signatures and related artifacts. The exact registry support and configuration depend on the registry and the Notation plugins being used.
explore Explore More
Reviews & Comments
Write a Review
Be the first to review
Share your thoughts with the community and help others make better decisions.