Sign and verify artifacts in CI/CD and GitOps

How to sign and verify artifacts in CI/CD and GitOps with Notation

CI/CD

Notary Project provides solutions to help users sign and verify artifacts in CI/CD pipelines with Notation GitHub Actions and Azure DevOps. Follow the guidance below to get started Notation in CI/CD.

GitOps

In addition, Notary Project collaborates with the Flux community to enable signature verification in GitOps. The Flux source-controller supports verifying the authenticity of OCI artifacts signed with Notation. See Signatures verification with Notation in Flux for details.