Ross ROSS = Recommend OSS · open-source software intelligence for agents

notaryproject/notary

Notary is a project that allows anyone to have trust over arbitrary collections of data observed · 2026-08-28

github.com/notaryproject/notary · Go · Apache-2.0 (permissive) · archived observed · 2026-08-28

Health v2 · maintenance only

10/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100

Flags: archived

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4093
  • days_rel: n/a
  • days_push: 756
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

3286 stars · 519 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Notary is a Go implementation of The Update Framework (TUF), providing a client and server for signing and verifying trusted collections of data. It is best known as the engine behind Docker Content Trust, enabling publishers to sign content offline and consumers to verify integrity even against compromised servers or mirrors.

Use cases

  • sign and verify container images with docker content trust
  • implement tuf-based software update security
  • protect software distribution against server compromise
  • manage signing keys with role-based key hierarchy
  • verify integrity of published content from untrusted mirrors

When to choose

  • you need TUF-compliant signing and verification of software artifacts
  • you use Docker Content Trust and need a notary server or client
  • you want survivable key compromise and role-separated signing keys

When to avoid

  • you need the newer Notation/Notary v2 OCI signature ecosystem instead
  • you only need simple checksum-based verification without key management
  • you need a general-purpose artifact registry rather than a trust server

Facets

application · maturity maintenance

security cryptography cli http-server security developer-tools windows go self-hosted tuf content-trust code-signing supply-chain-security docker-content-trust cncf containers linux macos docker

1 source

Member repositories

RepositoryRoleHealth v2
notaryproject/notarymain10

For agents

markdown · JSON · MCP: product_card(name="notaryproject/notary")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem