cosign container image signing tool rebuilt on Red Hat Hardened Images (RHHI)
1.5K
cosign is the Sigstore tool for signing and verifying container images and OCI artifacts. This image is rebuilt from source on Red Hat Hardened Images.
hi/go:latest-builder (build) → hi/core-runtime (runtime)build.yml-X sigs.k8s.io/release-utils/version.gitVersion-trimpath, local toolchain onlyCGO_ENABLED=1 and C libraries incompatible with the distroless runtime baseEvery image tag carries:
cosign verify-attestation --key <cosign.pub> --type cyclonedx <image>@<digest>
cosign verify-attestation --key <cosign.pub> --type slsaprovenance <image>@<digest>
Tags follow the pattern <upstream-version>-rhhi (e.g. v3.0.6-rhhi). Always pin by digest in production, not by tag.
Content type
Image
Digest
sha256:555cb6fe9…
Size
43.3 MB
Last updated
4 months ago
docker pull timothyswan/cosign:v3.0.6-rhhi