cosign

Container image signing and verification tool for supply chain security

brewmacoslinux
Try with needOr install directly
Source

About

Container Signing

Commands

cosign

Examples

Sign a container image with a private key$ cosign sign --key cosign.key ghcr.io/myorg/myimage:latest
Verify a container image signature$ cosign verify --key cosign.pub ghcr.io/myorg/myimage:latest
Generate a new signing key pair$ cosign generate-key-pair