technologyradartechnologyradar
Assess

Cosign allows us to sign container images as part of the CI pipeline and verify those signatures via admission controllers (like Kyverno) before execution (e.g. in Kubernetes). By leveraging OIDC-based "keyless" signing, we reduce the burden of key management while ensuring that only trusted, tamper-proof artifacts from our build pipelines are permitted to run in production clusters.