Ratify
Ratify is a CNCF Sandbox open-source verification framework for container images and other supply chain artifacts in Kubernetes environments. It enables policy-driven artifact ratification by coordinating any number of pluggable verifiers (signatures, SBOMs, scan results, attestations) against a given policy, integrating with Kubernetes admission webhooks via the Gatekeeper policy engine. Ratify is developed by the ratify-project GitHub organization (originally a Microsoft open-source project), written in Go, and distributed as a CLI tool, Go library, and Kubernetes admission webhook server. It supports OCI-compliant artifact stores including Azure Container Registry, Amazon ECR, and Docker Hub. Ratify exposes an internal HTTP verification API (v2alpha1) consumed by its webhook server but does not publish a public-facing REST API or OpenAPI specification.
Ratify is profiled on the APIs.io network. Tagged areas include Artifact Verification, CNCF, Cloud-Native, Container Security, and Kubernetes.
Ratify’s developer surface includes documentation, engineering blog, and 6 more developer resources.
Kin Score
Security Posture 1
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Resources
Documentation 1
Reference material describing how the API behaves
Build 3
SDKs, sample code, and the tooling you integrate with
Access & Security 1
Authentication, authorization, and security posture
Commercial 1
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API