Skip to main content

COSIGN_SHA256_AMD64

Constant COSIGN_SHA256_AMD64 

Source
pub const COSIGN_SHA256_AMD64: &str = "8b24b946dd5809c6bd93de08033bcf6bc0ed7d336b7785787c080f574b89249b";
Expand description

sha256 of the cosign-linux-amd64 binary at COSIGN_VERSION. Cloud-init verifies the downloaded binary against this before chmod+exec. Pinning the verifier itself closes the bootstrap-trust gap: TLS to github.com proves origin, sha256 proves bytes, then cosign proves the yubaba tarball.