Ratify currently publishes multiple forms of release assets both for production and development uses. Currently, these assets are not published with accompanying supply chain metadata including signatures, SBOMs, and provenance. Shipping each of these forms of metadata with all binaries and container images produced by Ratify will provide consumers a verifiable way to guarantee integrity of Ratify assets. Furthermore, this will improve Ratify's OSSF scorecard.
What does Ratify currently publish?
Ratify publishes two types: release and development. Release assets accompany official Ratify Github releases. Development assets are published weekly (or adhoc as needed).
Each publish type includes the following group of assets:
CRD container image to ghcr.io/ratify-project
Base container image to ghcr.io/ratify-project
Base + plugins container image to ghcr.io/ratify-project