I have many Docker images to maintain (mostly personal projects) but I have no way of verifying the authenticity of my images. To add an extra layer of security, I decided to POC the use of Cosign.
There are many alternatives, but some require the maintenance of a key management server or are just less popular than Cosign.