Ratify
Verifies artifacts and their referenced metadata at admission time in Kubernetes, so unsigned or unattested workloads never start.
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| Notary Project | verifies |
- Interfaces
container- Consumes
- oci-image, in-toto-attestation
- Emits
- json
- Runtime
- Needs network Deterministic Read-only Needs credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
- Website
- https://ratify.dev
- Repository
- https://github.com/notaryproject/ratify
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-09-17
- Stars
- 307 · last commit 2026-09-17
- Companies hiring
- 7 — distinct companies whose job postings name this tool, Q3-2026. A demand signal, not a deployment count.
- Also known as
- ratify
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.