Ratify
apartment
7 companies hiring
Radar: Developing
Apache-2.0
Verifies artifacts and their referenced metadata at admission time in Kubernetes, so unsigned or unattested workloads never start.
SecurityKubernetesSupply ChainPolicy EnforcementArtifact VerificationNotary Project
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| Notary Project | verifies |
Using this from an agent
- Interfaces
container- Consumes
- oci-image, in-toto-attestation
- Emits
- json
- Runtime
- Needs network Deterministic Read-only Needs credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
Block a deployment whose image is unsigned or fails policy, at the cluster boundary.
ci-pipeline
- Website
- https://ratify.dev
- Repository
- https://github.com/notaryproject/ratify
- License
- Apache-2.0 โ reported by the GitHub API, verified 2026-08-11
- Stars
- 308 ยท last commit 2026-08-11
- Companies hiring
- 7 โ distinct companies whose job postings name this tool, Q3-2026. A demand signal, not a deployment count.
- Also known as
- ratify
Reading this as an agent? Don't scrape the page โ this entry is published as
structured data at
arrow_back
All tools by adoption
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.