Currently the default for signature verification is disabled.
Because of security reasons, this default should be changed to always verify the signature.
IMPORTANT: Before changing the default to always verifying the signature, it is needed to double check if the signature verification for cosign tag-based signatures are working fine.
- relates to
-
CLID-289 As a user I would like to mirror the signatures of the container images
-
- Closed
-