A CLI tool to sign and verify artifacts
☆494Aug 25, 2026Updated this week
Alternatives and similar repositories for notation
Users that are interested in notation are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications.☆45Aug 3, 2026Updated 3 weeks ago
- Cross tooling and interoperability specifications☆177May 20, 2025Updated last year
- Azure Provider for Notation CLI☆17Nov 20, 2025Updated 9 months ago
- GitHub Actions for signing and verifying artifacts with Notation☆21Jan 12, 2026Updated 7 months ago
- Artifact Ratification Framework (CNCF Sandbox)☆307Updated this week
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Contains support for Notary Project signature envelope, and format specific implementation☆14Updated this week
- OCI registry client - managing content like artifacts, images, packages☆2,406Updated this week
- ☆65May 15, 2024Updated 2 years ago
- ORAS Go library☆284Updated this week
- Code signing and transparency for containers and binaries☆6,265Updated this week
- AWS Signer Plugin for Notation☆17Apr 21, 2026Updated 4 months ago
- go library for CBOR Object Signing and Encryption (COSE)☆66Updated this week
- Terraform provider to perform OCI image operations☆14Updated this week
- 🧵 CLI tool for directly patching container images!☆1,703Updated this week
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- in-toto is a framework to protect supply chain integrity.☆1,033Updated this week
- ☆27Aug 31, 2022Updated 3 years ago
- Software Supply Chain Transparency Log☆1,202Updated this week
- Sigstore OIDC PKI☆877Updated this week
- Trivy plugin for OCI referrers☆23May 13, 2024Updated 2 years ago
- Go implementation for CNAB content trust verification using TUF, Notary, and in-toto☆31Jul 5, 2023Updated 3 years ago
- A Kubewarden Policy that verifies all the signatures of the container images referenced by a Pod☆11Jan 20, 2026Updated 7 months ago
- 🐊 Policy Controller for Kubernetes☆4,269Updated this week
- Common go library shared across sigstore services and clients☆533Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆116Updated this week
- Notary is a project that allows anyone to have trust over arbitrary collections of data☆3,286Aug 7, 2024Updated 2 years ago
- Keyless Git signing using Sigstore☆1,118Updated this week
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆34Apr 22, 2025Updated last year
- in-toto Attestation Framework☆369Updated this week
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆546Updated this week
- Unified Policy as Code☆8,084Updated this week
- An admission controller that integrates Container Image Signature Verification into a Kubernetes cluster☆478Updated this week
- All-in-one Kubernetes access manager. User-level credentials, RBAC, SSO, audit logs.☆1,209Jun 16, 2026Updated 2 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- zot - A scale-out production-ready vendor-neutral OCI-native container image/artifact registry (purely based on OCI Distribution Specific…☆2,669Updated this week
- ☆260Updated this week
- 📦 Produce secure packages and containers with declarative configurations☆319Updated this week
- Go library for Sigstore signing and verification☆17Sep 29, 2023Updated 2 years ago
- A utility to generate SPDX-compliant Bill of Materials manifests☆466Updated this week
- ORAS (OCI registry as storage) container storage interface☆17Jun 5, 2024Updated 2 years ago
- Integrates Spiffe and Vault to have secretless authentication☆101Updated this week