Container Image Signing and Verification: Using cosign to Guard the Last Gate of Supply Chain Security
Overview Let me start with a story that still haunts me. Last year, our internal image registry had a permissions misconfiguration that was loose for several days. Post-incident review found no evidence of tampering, but those few days had me on edge — what if someone had pushed an image with the same tag, replacing app:latest with their own version? Our deployment pipeline would have pulled and run it just the same....