pub const COSIGN_SHA256_AMD64: &str = "4629c757b7618056f8ddd7e2625ae9fdd94c0372a65049520bc7d9df9efc7f71";Expand description
sha256 of the cosign-linux-amd64 binary at COSIGN_VERSION, from
cosign’s own published cosign_checksums.txt for that release. Cloud-init
verifies the downloaded binary against this before chmod+exec. Pinning the
verifier itself closes the bootstrap-trust gap: TLS to github.com proves
origin, sha256 proves bytes, then cosign proves the yubaba tarball.