We want to use Cosign to sign released binary and container images. The upstream project also uses Cosign for signing their releases and it makes sense to remain closely aligned as much as possible.
Cosign has wide adoption in the CNCF ecosystem so this is a no-brainer.
We want to use Cosign to sign released binary and container images. The upstream project also uses Cosign for signing their releases and it makes sense to remain closely aligned as much as possible.
Cosign has wide adoption in the CNCF ecosystem so this is a no-brainer.