Changelog
- [3c7c1c] ci, feat - allow explicitly setting the container image (#577)
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
:::bash
cosign verify-blob checksums.txt --signature=checksums.txt.sig --key https://artifacts.fairwinds.com/cosign-p256.pub
cosign verify us-docker.pkg.dev/fairwinds-ops/oss/pluto:v5 --key https://artifacts.fairwinds.com/cosign-p256.pub