Skip to main content

COSIGN_SHA256_AMD64

Constant COSIGN_SHA256_AMD64 

Source
pub const COSIGN_SHA256_AMD64: &str = "4629c757b7618056f8ddd7e2625ae9fdd94c0372a65049520bc7d9df9efc7f71";
Expand description

sha256 of the cosign-linux-amd64 binary at COSIGN_VERSION, from cosign’s own published cosign_checksums.txt for that release. Cloud-init verifies the downloaded binary against this before chmod+exec. Pinning the verifier itself closes the bootstrap-trust gap: TLS to github.com proves origin, sha256 proves bytes, then cosign proves the yubaba tarball.