podman image verify vs. external Cosign for multi-signature images
0 reputation · 27 Aug 2025, 01:55 UTC
Goal
A container workflow using Podman 4.0+ requires validation of OCI image signatures. The images in this environment are signed by multiple entities, such as a build pipeline and a security auditor, resulting in multiple signatures per image.
Constraints
The built-in podman image verify command leverages the Cosign library but is documented to process only the first signature in the signature list. In contrast, the standalone Cosign CLI supports full verification of all signatures, keyless verification, and attestations, but introduces an external binary dependency and separate key management.
- Does
podman image verifysilently ignore subsequent signatures, or does it return a specific warning when multiple signatures are present? - Is there a configuration within Podman 4.x to enable the evaluation of all signatures, or is the external Cosign CLI the only documented method for multi-signature validation?