pub const COSIGN_SHA256_AMD64: &str = "8b24b946dd5809c6bd93de08033bcf6bc0ed7d336b7785787c080f574b89249b";Expand description
sha256 of the cosign-linux-amd64 binary at COSIGN_VERSION. Cloud-init
verifies the downloaded binary against this before chmod+exec. Pinning the
verifier itself closes the bootstrap-trust gap: TLS to github.com proves
origin, sha256 proves bytes, then cosign proves the yubaba tarball.