PageSourceSearch

https://ratify.dev/assets/js/e08b7ce3.a3d69d3b.js

js ratify.dev collected 2026-09-24 19:28:46 UTC 6,123 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkratify=globalThis.webpackChunkratify||[]).push([[3300],{18992(e,t,i){i.r(t),i.d(t,{assets:()=>c,contentTitle:()=>a,default:()=>h,frontMatter:()=>o,metadata:()=>r,toc:()=>d});const r=JSON.parse('{"id":"plugins/verifier/notation","title":"Notation","description":"notation is a built-in Ratify verifier that validates Notary Project signatures. It uses X.509 PKI with a trust store (certificates) and trusted identities to determine whether a signed artifact is authentic.","source":"@site/versioned_docs/version-2.0.0-beta.1/plugins/verifier/notation.md","sourceDirName":"plugins/verifier","slug":"/plugins/verifier/notation","permalink":"/docs/2.0.0-beta.1/plugins/verifier/notation","draft":false,"unlisted":false,"editUrl":"https://github.com/ratify-project/ratify-web/blob/main/versioned_docs/version-2.0.0-beta.1/plugins/verifier/notation.md","tags":[],"version":"2.0.0-beta.1","sidebarPosition":1,"frontMatter":{"sidebar_position":1},"sidebar":"tutorialSidebar","previous":{"title":"Verifiers","permalink":"/docs/2.0.0-beta.1/plugins/verifier/"},"next":{"title":"Cosign","permalink":"/docs/2.0.0-beta.1/plugins/verifier/cosign"}}');var n=i(74848),s=i(28453);const o={sidebar_position:1},a="Notation",c={},d=[{value:"Configuration",id:"configuration",level:2},{value:"Parameters",id:"parameters",level:3}];function l(e){const t={a:"a",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",p:"p",pre:"pre",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,s.R)(),...e.components};return(0,n.jsxs)(n.Fragment,{children:[(0,n.jsx)(t.header,{children:(0,n.jsx)(t.h1,{id:"notation",children:"Notation"})}),"\n",(0,n.jsxs)(t.p,{children:[(0,n.jsx)(t.code,{children:"notation"})," is a built-in Ratify verifier that validates ",(0,n.jsx)(t.a,{href:"https://notaryproject.dev/",children:"Notary Project"})," signatures. It uses X.509 PKI with a trust store (certificates) and trusted identities to determine whether a signed artifact is authentic."]}),"\n",(0,n.jsxs)(t.p,{children:["In Ratify v2 the verifier is configured inline in the ",(0,n.jsx)(t.code,{children:"verifiers"})," list of an ",(0,n.jsx)(t.a,{href:"/docs/2.0.0-beta.1/concepts/executor",children:"Executor"}),"; there is no separate ",(0,n.jsx)(t.code,{children:"Verifier"})," CRD."]}),"\n",(0,n.jsx)(t.h2,{id:"configuration",children:"Configuration"}),"\n",(0,n.jsx)(t.pre,{children:(0,n.jsx)(t.code,{className:"language-yaml",children:'apiVersion: config.ratify.sh/v2alpha1\nkind: Executor\nmetadata:\n  name: executor-notation\nspec:\n  scopes:\n    - registry.example.com\n  verifiers:\n    - name: notation-verifier\n      type: notation\n      parameters:\n        scopes:\n          - registry.example.com\n        trustedIdentities:\n          - "*"\n        certificates:\n          - type: ca\n            inline:\n              certs: |\n                -----BEGIN CERTIFICATE-----\n                ...\n                -----END CERTIFICATE-----\n  stores:\n    - type: registry-store\n      parameters:\n        credential:\n          provider: static\n'})}),"\n",(0,n.jsx)(t.h3,{id:"parameters",children:"Parameters"}),"\n",(0,n.jsxs)(t.table,{children:[(0,n.jsx)(t.thead,{children:(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.th,{children:"Field"}),(0,n.jsx)(t.th,{children:"Required"}),(0,n.jsx)(t.th,{children:"Description"})]})}),(0,n.jsxs)(t.tbody,{children:[(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.td,{children:(0,n.jsx)(t.code,{children:"scopes"})}),(0,n.jsx)(t.td,{children:"no"}),(0,n.jsxs)(t.td,{children:["Scopes this verifier applies to. Defaults to the executor scopes. See the ",(0,n.jsx)(t.a,{href:"https://github.com/notaryproject/specifications/blob/v1.1.0/specs/trust-store-trust-policy.md#trust-policy-constraints",children:"Notation trust policy constraints"}),"."]})]}),(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.td,{children:(0,n.jsx)(t.code,{children:"trustedIdentities"})}),(0,n.jsx)(t.td,{children:"no"}),(0,n.jsxs)(t.td,{children:["Identities trusted to produce signatures. See ",(0,n.jsx)(t.a,{href:"https://github.com/notaryproject/specifications/blob/v1.1.0/specs/trust-store-trust-policy.md#trusted-identities-constraints",children:"trusted identities"}),"."]})]}),(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.td,{children:(0,n.jsx)(t.code,{children:"certificates"})}),(0,n.jsx)(t.td,{children:"yes"}),(0,n.jsx)(t.td,{children:"One or more certificate sources that make up the trust store."})]})]})]}),"\n",(0,n.jsxs)(t.p,{children:["Each ",(0,n.jsx)(t.code,{children:"certificates"})," entry has:"]}),"\n",(0,n.jsxs)(t.ul,{children:["\n",(0,n.jsxs)(t.li,{children:[(0,n.jsx)(t.code,{children:"type"})," \u2014 trust-store type: ",(0,n.jsx)(t.code,{children:"ca"}),", ",(0,n.jsx)(t.code,{children:"signingAuthority"}),", or ",(0,n.jsx)(t.code,{children:"tsa"})," (for timestamping). See ",(0,n.jsx)(t.a,{href:"https://github.com/notaryproject/specifications/blob/v1.1.0/specs/trust-store-trust-policy.md#version-10",children:"Notation trust stores"}),"."]}),"\n",(0,n.jsxs)(t.li,{children:["One key provider that supplies the certificates: ",(0,n.jsx)(t.code,{children:"inline"})," (with a ",(0,n.jsx)(t.code,{children:"certs"})," field holding the PEM string), ",(0,n.jsx)(t.code,{children:"files"})," (list of paths), or ",(0,n.jsx)(t.code,{children:"azurekeyvault"}),"."]}),"\n"]}),"\n",(0,n.jsxs)(t.p,{children:["See ",(0,n.jsx)(t.a,{href:"/docs/2.0.0-beta.
11/ratify-configuration#notation-verifier",children:"Configuration \u2192 Notation Verifier"})," for advanced examples, including multiple key providers and Azure Key Vault."]})]})}function h(e={}){const{wrapper:t}={...(0,s.R)(),...e.components};return t?(0,n.jsx)(t,{...e,children:(0,n.jsx)(l,{...e})}):l(e)}},28453(e,t,i){i.d(t,{R:()=>o,x:()=>a});var r=i(96540);const n={},s=r.createContext(n);function o(e){const t=r.useContext(s);return r.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function a(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(n):e.components||n:o(e.components),r.createElement(s.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.