< BLOG HOME

Mirantis Secure Registry 2.10 Delivers Cosign, Modern Scanning, and a Clear Path Beyond Docker Content Trust

Mirantis Secure Registry logo with 2.10 release number

Mirantis has released Mirantis Secure Registry (MSR) 2.10 for organizations running MSR on Mirantis Kubernetes Engine (MKE). While MSR 2.9 added Helm chart support and Running Image Enforcement, 2.10 tackles two issues that matter most in 2026. First, Docker Content Trust (DCT) is being retired from the Docker project, with Cosign becoming the new industry standard for image signing. Secondly, the quickening pace of security vulnerability discovery (i.e., CVEs) requires constant vigilance and the latest scanning tools.

If you are on MSR 2.9, upgrading to 2.10 keeps your registry current, scannable, and signable while you continue planning your upgrade to MSR 4.

Docker Content Trust is deprecated

Docker Content Trust, backed by Notary, has been the standard for signing images in MSR for years. That era is ending. As the open-source community is dropping support for Notary, MSR will likewise retire support for it as well. As of July 2026, DCT is considered deprecated across Mirantis releases. Complete removal from the product is planned around 2028.

If you are currently using DCT, don’t worry. Notary-active MSR 2.9 instances will maintain DCT across the upgrade to 2.10. Upgraded instances support both the new Cosign paradigm as well as the legacy Notary signatures. This will provide time to plan for the migration to Cosign and eventual removal of DCT from the system.

Recommended migration path for signing customers:

  1. Upgrade to MSR 2.10

  2. Start Cosign signing for new pushes

  3. Re-sign critical DCT-signed images

    • It is not possible to convert Notary signatures to Cosign, so resigning will be necessary.

  4. Enable Cosign enforcement in MKE 3.9.5

  5. Disable Notary via the Admin Settings page once it is no longer in use

For new, non-upgrade installations of MSR 2.10, or for 2.9 upgrades that currently do not contain Notary signatures, the DCT system will be automatically and permanently disabled. Cosign should be utilized for future image signing efforts.

Cosign: the new standard for image signing

MSR 2.10 adds Cosign support, aligned with the Sigstore ecosystem and with MKE 3.9.5 runtime enforcement.

Why Cosign over DCT:

  • Signatures are stored as OCI artifacts in the registry, no separate Notary server or trust database to operate.

  • Works with the standard cosign CLI and modern CI/CD tooling.

  • Supports keyless signing when OIDC identity fits your workflow. Traditional key-based signing is still available for environments that require it (e.g. air-gapped).

  • MSR lifecycle is Cosign-aware. Image pruning and garbage collection operations clear away related signature artifacts when the primary artifacts are removed.

  • Aligns with MCR 29 and MSR 4 (Harbor-based), so skills transfer when you migrate.

MKE 3.9.5 completes the loop: Cosign runtime verification replaces DCT-based “run only trusted images” enforcement. Sign in the registry, enforce on the cluster.

Updated vulnerability scanner

MSR 2.10 received major improvements and upgrades in the vulnerability scanning. The new scanner is more performant and includes two years of enhancements in one release.

Customers upgrading gain:

  • Broader detection (Go, .NET, Rust, OpenWRT, and more)

  • Fewer false positives (Chainguard/Wolfi, Minimus, Wind River feeds)

  • More accurate recognition of Linux vendor security patches

The upgrade is non-disruptive: MSR 2.10 maintains backward compatibility with existing CVE databases, so there is no forced rescan cliff. If you use Running Image Enforcement from 2.9, your policies simply operate on better data.

Platform refresh and easy upgrade

MSR 2.10 also updates underlying platform components, including Go 1.25, Alpine 3.23, TLS compliance fixes, and CVE remediation across MSR services. For regulated environments, 2.10 closes the gap on aging components without changing day-to-day registry operations.

The upgrade follows the same process as prior 2.x releases.

Upgrade to MSR 2.10 today

MSR 2.10 gives customers a registry that scans with a current engine and supports signing with an industry-standard tool. For more information, refer to the following resources:

Mirantis simplifies Kubernetes.

From the world’s most popular Kubernetes IDE to fully managed services and training, we can help you at every step of your K8s journey.

Connect with a Mirantis expert to learn how we can help you.

CONTACT US
k8s-callout-bg.png