Product1 publisher3 min readPublished
Docker puts Verified Publisher behind a signup form, and pull data behind a plan
Verified Publisher applications are now self-serve with two plans, priority search ranking and reports that name the companies pulling your images.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Applying to become a Docker Verified Publisher is now self-serve; vendors can apply directly in Docker Hub.
- Docker states that its team still evaluates every single DVP application manually.
- Verification is done by the Docker team, and applicants get a checkout link as soon as they are approved.
- Within the new self-serve process, applicants can choose between two different plans.
- Previously, companies interested in becoming a Docker Verified Publisher needed to contact Docker's sales team to be considered for the program.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Docker has made applications to its Verified Publisher program self-serve: vendors apply inside Docker Hub, Docker staff still review each application by hand, and approved applicants get a checkout link and a choice between two plans [1][2][3][4]. Until now, getting considered meant contacting Docker's sales team, so the change converts publisher identity from a negotiated partnership into a product with a signup flow [5][1].
What an accepted publisher buys is visibility and measurement. Verified organisations earn verified status plus prioritised search ranking, so developers comparing options on Hub see that content first [6]. Summary and trends reports show which repositories are gaining ground and where adoption is shifting across versions and releases [7]. Tracked-company reports, which Docker says sit on the Growth plan, turn anonymous pull traffic into named companies so that teams already running your software surface in your sales and partner pipeline [8]. Docker's own phrasing is that this makes Hub a trusted, discoverable and measurable distribution channel and turns open-source reach into a commercial pipeline [9]. That is a distribution-and-attribution product wearing a trust badge, and it is worth reading it as both.
The rationale Docker gives is machine-speed selection: when software is chosen by tooling rather than browsed by humans, the question stops being "is this popular?" and becomes "do we know who published this?" [10]. The badge answers exactly that narrow question, since it certifies that Docker manually reviewed the publisher and confirmed they are who they claim to be [11]. The scope has widened past container images. Docker says developers now come to Hub for MCP servers, models, sandboxes and agents, and that DVP is deliberately one review and one badge across every content type [12]. For a vendor shipping an MCP server this year, that means verification earned on images travels with the next artifact type.
Docker is unusually direct about the limits. It states that pulling from Verified Publishers is only a step towards a better security posture and needs pairing with reviewing the specific artifact, pinning to digests rather than mutable tags, verifying provenance and signatures at the image level, and checking for CVEs [13]. In other words the badge attests to the identity of a company, not to the contents of the tag you resolved this morning [3]. Named publishers already in the programme include Google, Microsoft, AWS, Datadog, Grafana Labs and n8n [14].
Two things the announcement leaves out: it does not state plan pricing, does not name both tiers beyond the reference to Growth, and gives no review turnaround or published verification criteria [15]. And the ranking benefit is now reachable through a checkout, which means search prominence on Hub correlates in part with willingness to pay for a plan [2]. Docker also says it is continuing to build stronger, more secure publishing flows across Hub, without detail [16].
Watch whether agent frameworks and MCP catalogues start reading the DVP badge programmatically as a selection filter, because that is where a manual identity check turns into automated procurement policy. Watch for published criteria and review times, since a manual review with no stated bar is hard for a buyer to reason about [2][15]. And watch how enterprises react to learning that their pull traffic is being resolved into named companies for vendor pipelines [8]. Applications open from the Explore page in Docker Hub [17].