podman image verify vs. external Cosign for multi-signature images
Goal A container workflow using Podman 4.0+ requires validation of OCI image signatures. The images in this environment are signed by multiple entities, such as a build pipeline and a security auditor, resulting in multiple signatures per image. Constraints The built-in podman image verify command leverages the Cosign library but is documented to process onl