PageSourceSearch

https://ratify.dev/assets/js/b193c361.ce0fb8fd.js

js ratify.dev collected 2026-09-24 19:28:33 UTC 11,456 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkratify=globalThis.webpackChunkratify||[]).push([[3109],{28453(e,t,i){i.d(t,{R:()=>s,x:()=>o});var r=i(96540);const n={},a=r.createContext(n);function s(e){const t=r.useContext(a);return r.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function o(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(n):e.components||n:s(e.components),r.createElement(a.Provider,{value:t},e.children)}},37692(e){e.exports=JSON.parse('{"permalink":"/blog/ratify-v1.3.0-is-available","editUrl":"https://github.com/ratify-project/ratify-web/blog/2024-09-16-ratify-1.3.0.mdx","source":"@site/blog/2024-09-16-ratify-1.3.0.mdx","title":"Ratify v1.3.0 is available!","description":"We are excited to announce the release of Ratify v1.3.0!","date":"2024-09-16T00:00:00.000Z","tags":[{"inline":true,"label":"verification","permalink":"/blog/tags/verification"}],"readingTime":4.43,"hasTruncateMarker":false,"authors":[{"name":"Ratify maintainers","url":"https://github.com/ratify-project/ratify","imageURL":"https://raw.githubusercontent.com/deislabs/ratify/main/logo.svg","key":"ratify","page":null}],"frontMatter":{"slug":"ratify-v1.3.0-is-available","title":"Ratify v1.3.0 is available!","authors":["ratify"],"tags":["verification"]},"unlisted":false,"prevItem":{"title":"Announcing Ratify v1.4.0 - Revocation Checking with CRL Support, Enhanced Out-of-box Experience, and New Cloud Provider Support","permalink":"/blog/ratify-v1.4.0-is-available"},"nextItem":{"title":"Ratify v1.2.0 is available!","permalink":"/blog/ratify-v1.2.0-is-available"}}')},76877(e,t,i){i.r(t),i.d(t,{assets:()=>c,contentTitle:()=>o,default:()=>u,frontMatter:()=>s,metadata:()=>r,toc:()=>l});var r=i(37692),n=i(74848),a=i(28453);const s={slug:"ratify-v1.3.0-is-available",title:"Ratify v1.3.0 is available!",authors:["ratify"],tags:["verification"]},o=void 0,c={authorsImageUrls:[void 0]},l=[{value:"Features and deprecations",id:"features-and-deprecations",level:2},{value:"Support of validating Notary Project signatures with timestamping",id:"support-of-validating-notary-project-signatures-with-timestamping",level:3},{value:"Support of periodic retrieval of keys and certificates stored in a KMS",id:"support-of-periodic-retrieval-of-keys-and-certificates-stored-in-a-kms",level:3},{value:"Introducing new configuration for Cosign keyless verification",id:"introducing-new-configuration-for-cosign-keyless-verification",level:3},{value:"Other enhancements",id:"other-enhancements",level:2},{value:"Improving error messages for artifact verification",id:"improving-error-messages-for-artifact-verification",level:3},{value:"Enhancing security",id:"enhancing-security",level:3},{value:"Acknowledgements",id:"acknowledgements",level:2},{value:"Try it now",id:"try-it-now",level:2}];function d(e){const t={a:"a",code:"code",h2:"h2",h3:"h3",li:"li",p:"p",strong:"strong",ul:"ul",...(0,a.R)(),...e.components};return(0,n.jsxs)(n.Fragment,{children:[(0,n.jsxs)(t.p,{children:["We are excited to announce the release of ",(0,n.jsx)(t.a,{href:"https://github.com/ratify-project/ratify/releases/tag/v1.3.0",children:"Ratify v1.3.0"}),"!"]}),"\n",(0,n.jsxs)(t.p,{children:["Ratify is now a CNCF sandbox project! We sincerely thank the exceptional community for invaluable contributions and unwavering support in reaching this significant milestone.\r\nRatify is a verification framework that ensures container images and supply chain artifacts stored in a registry are thoroughly vetted and trustworthy.\r\nBy ",(0,n.jsx)(t.a,{href:"https://notaryproject.dev/blog/2023/announcing-major-release/#integration-with-admission-controller-for-kubernetes-usage",children:"integrating Ratify into your Kubernetes"})," workflow,\r\nyou can safeguard your application deployment against potential threats and vulnerabilities, thereby greatly enhancing the security of your applications."]}),"\n",(0,n.jsx)(t.p,{children:"Read further to learn about the exciting new features and how they can be beneficial to you!"}),"\n",(0,n.jsx)(t.h2,{id:"features-and-deprecations",children:"Features and deprecations"}),"\n",(0,n.jsx)(t.p,{children:"Key features in this release include:"}),"\n",(0,n.jsxs)(t.ul,{children:["\n",(0,n.jsx)(t.li,{children:"Support of validating Notary Project signatures with timestamping"}),"\n",(0,n.jsx)(t.li,{children:"Support of periodic retrieval of keys and certificates stored in a KMS (Key Management System)"}),"\n",(0,n.jsx)(t.li,{children:"Introducing new configuration for Cosign keyless verification"}),"\n"]}),"\n",(0,n.jsx)(t.h3,{id:"support-of-validating-notary-project-signatures-with-timestamping",children:"Support of validating Notary Project signatures with timestamping"}),"\n",(0,n.jsxs)(t.p,{children:["Ratify now supports verifying Notary Project signatures with timestamping.\r\nSince ",(0,n.jsx)(t.a,{href:"https://notaryproject.dev/blog/2024/announcing-notation-v1-2/",children:"Notation v1.2.0 release"}),", Notary Project supports ",(0,n.jsx)(t.a,{href:"https://www.rfc-editor.org/rfc/rfc3161",children:"RFC 3161"}),"-compliant timestamping.\r\nThis enhancement extends the trust of signatures created within the certificate's validity period by trusting on a Timestamping Authority (TSA),\r\nenabling successful signature verification even after the certificates have expired.\r\nTimestamping reduces costs by eliminating the need to periodically re-sign images due to certificate expiry, which is critical when using short-lived certificates.\r\nTo validate Notary Project signatures that include timestamps from a TSA, it's essential for a verifier to determine trusted entities both as the image signer and as the TSA. In Ratify, trust stores and trust policies can be configured in the Notation verifier to establish this trust. For more information, see the ",(0,n.jsx)(t.a,{href:"https://ratify.dev/docs/next/plugins/verifier/notation/#configuration",children:"configuration of Notation verifier"}),"."]}),"\n",(0,n.jsx)(t.h3,{id:"support-of-periodic-retrieval-of-keys-and-certificates-stored-in-a-kms",children:"Support of periodic retrieval of keys and certificates stored in a KMS"}),"\n",(0,n.jsxs)(t.p,{children:["Users configure keys and certificates through Key Management Providers (KMP) resources for signature verification. Without specifying versions in KMP resources, Ratify fetches the latest versions. Keys or certificates may rotate for security reasons, and automatic rotation is a common practice. When rotated, new versions are created, making the current versions outdated. Before Ratify v1.3.0, users had to manually update KMP resources when versions were rotated or disabled. This could result in verification failures for new versions if updates were not performed promptly. From v1.3.0 onwards, the ",(0,n.jsx)(t.code,{children:"refreshInterval"})," parameter is introduced for KMP resources allowing periodic checks for the latest versions and status validation. Future updates will also support keeping a specified number of previous versions to validate older signatures that may still be in use."]}),"\n",(0,n.jsxs)(t.p,{children:["Please note that currently, only the KMP of Azure Key Vault has this support. Let us know if you need support for other KMPs. For more information, see the ",(0,n.jsx)(t.a,{href:"https://ratify.dev/docs/next/reference/custom%20resources/key-management-providers#azure-key-vault",children:"Azure Key Vault KMP configuration"}),"."]}),"\n",(0,n.jsx)(t.h3,{id:"introducing-new-configuration-for-cosign-keyless-verification",children:"Introducing new configuration for Cosign keyless verification"}),"\n",(0,n.jsxs)(t.p,{children:["Starting with version 1.2.0, trust policies have been introduced for Cosign signature verification, allowing users to fine tune verification policies. This release enhances the feature by adding support for Cosign keyless verification. For more information, see the ",(0,n.jsx)(t.a,{href:"https://ratify.dev/docs/next/plugins/verifier/cosign#keyless",children:"Cosign verifier keyless configuration"}),"."]}),"\n",(0,n.jsx)(t.h2,{id:"other-enhancements",children:"Other enhancements"}),"\n",(0,n.jsx)(t.h3,{id:"improving-error-messages-for-artifact-verification",children:"Improving error messages for artifact verification"}),"\n",(0,n.jsxs)(t.p,{children:["Clear and concise error messages help users understand what went wrong and how to fix it, reducing support requests and downtime. For developers, well-written error messages provide specific details that can assist in diagnosing and resolving bugs or system issues. Improving error messages is an ongoing initiative at Ratify project. In this release, we've refined the error messages related to artifact verification as per the ",(0,n.jsx)(t.a,{href:"https://github.com/notaryproject/ratify/blob/v1.3.0/docs/proposals/Error-Messages-Improvements.md",children:"proposal"}),"."]}),"\n",(0,n.jsx)(t.h3,{id:"enhancing-security",children:"Enhancing security"}),"\n",(0,n.jsx)(t.p,{children:"Since this release, we have strengthened the security posture of the Ratify project through several key implementations:"}),"\n",(0,n.jsxs)(t.p,{children:[(0,n.jsx)(t.strong,{children:"Docker Build Attestations"}),": We now generate attestations, including provenance and a Software Bill of Materials (SBOM), for Ratify dev images. This improves transparency in the build process, ensuring better traceability and accountability of image contents. For more information, see the ",(0,n.jsx)(t.a,{href:"https://ratify.dev/docs/next/troubleshoot/security/#build-attestations",children:"Build attestations document"}),"."]}),"\n",(0,n.jsxs)(t.p,{children:[(0,n.jsx)(t.strong,{children:"Image Signing"}),": Ratify dev images are now signed to ensure their integrity and authenticity. This helps defend against supply chain attacks by preventing tampered or untrusted images from being deployed in production environments. For more information, see the ",(0,n.jsx)(t.a,{href:"https://ratify.dev/docs/next/troubleshoot/security/#signature-validation",children:"Signature Validation document"}),"."]}),"\n",(0,n.jsxs)(t.p,{children:[(0,n.jsx)(t.strong,{children:"Vulnerability Scanning Workflow"}),": We've implemented an automated workflow to scan Go projects, their dependencies, and Ratify images for known vulnerabilities. This proactive measure ensures that any potential security issues are identified and addressed early."]}),"\n",(0,n.jsxs)(t.p,{children:[(0,n.jsx)(t.strong,{children:"OpenSSF Best Practices Badge"}),": By adopting the Open Source Security Foundation (OpenSSF) best practices, we've earned the best practices badge. This reflects our commitment to industry-standard security practices, enhancing the project's trustworthiness and overall security posture."]}),"\n",(0,n.jsx)(t.h2,{id:"acknowledgements",children:"Acknowledgements"}),"\n",(0,n.jsx)(t.p,{children:"The Ratify release team wants to thank the entire Ratify community for all the activities and engagements that has been vital for helping the project grow and reach this milestone."}),"\n",(0,n.jsx)(t.h2,{id:"try-it-now",children:"Try it now"}),"\n",(0,n.jsxs)(t.p,{children:["Follow this ",(0,n.jsx)(t.a,{href:"https://ratify.dev/docs/next/quick-start",children:"quick start guide"})," to try out Ratify v1.3.0."]})]})}function u(e={}){const{wrapper:t}={...(0,a.R)(),...e.components};return t?(0,n.jsx)(t,{...e,children:(0,n.jsx)(d,{...e})}):d(e)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.