-
Notifications
You must be signed in to change notification settings - Fork 555
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Why not use Notary v2? #423
Comments
Hey @AlekSi! The simple answer is that you can't use notary v2 right now :) Many of us are actively engaged in the Notary V2 working groups, but I don't have a clear enough picture of what that project is intending to eventually build/become to write a detailed explanation of the differences. My hope is that we can eventually align on an interoperable signature format, see some of my proposals over there: |
The first FAQ entry tells me that I can't (should not) use cosign too. https://www.docker.com/blog/secure-software-supply-chain-best-practices/ tells me
You plan to release 1.0.0 this month. I… just don't understand how two projects that are so close to shipping are not compared in the README / FAQ. As a user, I'm looking for that information. |
I can't really comment on that blog post, other than to say that it's quite far from my understanding of the state of the notary v2 project. Here's my understanding of the differences as of today, July 8th: Cosign
Notary V2
|
Just want to point out that there's a whole sea of difference between "this software has been released a couple of times, and is about to reach API stability" with "there's a blogpost somewhere that promises that they will work very hard to release something in 'a few months if all is well'" Part of the challenge is that there is no public Notary V2 design yet (at least that I'm aware of). I can't tell you why or why not use a product that does not exist. Admittedly, Half-Life 3 always sounded good, but I can't recommend that one either. |
Update: now that the notation alpha is out I'm working on a document to compare these and will share when it's finished. I've asked some of the notary maintainers to review it as well. If you'd like to help review or edit before it's finished, please let me know and I'll add you to the document! |
Count me in after it's finished |
I'd love to read up on the comparison between notation alpha and cosign and to help however I can. Please count me in too! |
The draft is almost ready and I'm going to be publishing it tomorrow. Thanks everyone for the reviews! |
Closing with #1014. |
The most interesting FAQ entry is empty: https://github.com/sigstore/cosign#why-not-use-notary-v2
The text was updated successfully, but these errors were encountered: