Marcio Cunha

Continuous Container Image Auditing with SBOM and Cosign Digital Signatures

Learn how to mitigate vulnerabilities in corporate environments by integrating SBOM generation with Cosign and Sigstore digital signatures to ensure container integrity.

Marcio Cunha•5 min
Also available in:EspañolPortuguês
Summary
  • Transparency in the software supply chain relies on structured inventories known as SBOMs.
  • Digital signing of artifacts with Cosign eliminates local private key dependencies using OIDC identities.
  • Continuous auditing turns static security policies into dynamic, automated barriers within the pipeline.
  • Decentralized edge verification prevents the execution of tampered images even after initial deployment.
  • Combining inventory and cryptographic signatures forms the foundation for rigorous regulatory compliance.

The Challenge of the Container Software Supply Chain

Managing packaged applications in modern environments requires going far beyond simply executing code. In practice, this means that every container carries dozens or hundreds of third-party libraries, minimal operating systems, and utilities that can hide critical security flaws. When a vulnerability emerges in an obscure dependency, entire teams panic trying to figure out where that component was used. The current ecosystem demands total visibility and cryptographic assurance that the code executed in production is exactly what was built by the engineering team, without any unwanted alterations along the way.

To solve this visibility problem, modern engineering has adopted the concept of SBOM, which essentially acts as an ultra-detailed medication leaflet or a nutritional ingredient list. It is a file in a standardized format that exhaustively lists every package, version, license, and dependency present in a container image. Having this inventory does not eliminate flaws by itself, but it transforms the chaos of a blind search into a surgical consultation. Knowing exactly what is running, automated tools can cross-reference vulnerability databases in seconds and point out precisely where the fix must be applied.

Generating Reliable Inventories with Open Standards

The creation of the dependency inventory must be automated within the continuous integration flow, ensuring that no artifact is generated without its respective structured documentation. Tools like Syft analyze the image file system and generate the SBOM in globally recognized formats like SPDX or CycloneDX. In practice, this step occurs right after package construction, attaching the inventory as an inseparable metadata of the application lifecycle. Without this rigorous automation, the inventory quickly becomes outdated, rendering it useless against the dynamism of daily software updates.

Once the inventory is available, the next critical step is to ensure that both it and the image itself are not tampered with during transport to the central image registry. This is where digital signatures come in, a mathematical mechanism that seals the content inviolably. If someone modifies a single byte in the image or tries to forge the SBOM after construction, the signature instantly loses validity. This mechanism protects against repository intrusions and ensures that the cluster execution engine trusts only legitimate artifacts, rejecting any suspicious entry before even attempting to start the container.

Cryptographic Signing Without Complex Key Management Using Sigstore and Cosign

Historically, managing cryptographic keys to sign code was a monumental headache for infrastructure teams. It required creating asymmetric key pairs, distributing them securely, rotating them periodically, and praying that no one lost the master password or left a private key exposed in a public repository. The Sigstore project and its core tool, Cosign, revolutionized this dynamic by introducing signature generation based on ephemeral identities and federated authentication. In practice, the developer or pipeline authenticates using their corporate account via OIDC, issuing a very short-lived certificate that signs the container and leaves an immutable public log.

Using Cosign drastically simplifies the implementation of large-scale security policies, allowing verification to be natively integrated into orchestration platforms like Kubernetes. Below is a practical example of how to sign an image using an identity validated by cloud providers:

cosign sign --key oidc://token.actions.githubusercontent.com registry.example.com/app/service:v1.2.0

This command interacts with the certificate issuance service, validates the issuer identity through the CI/CD environment token, and applies the digital signature directly to the associated image registry. From this moment on, the image has a cryptographic origin guarantee that can be validated by any infrastructure component before authorizing its loading.

Continuous Auditing and Admission Policies in Distributed Environments

Signing images and generating inventories becomes meaningless if the infrastructure does not verify these guarantees before running the container. Continuous auditing and the application of admission policies act like the bouncer at the door of an exclusive club, barring any artifact that lacks the correct credential and a clean vulnerability history. Policy tools like Kyverno or OPA Gatekeeper intercept pod creation requests in the cluster and check the current state of the image, requiring it to possess a valid signature issued by a trusted entity and an SBOM containing no unmitigated critical flaws.

To ensure the process runs consistently across all cluster nodes, validation can be automated with Cosign itself during provisioning. Here is how to configure verification in a pre-check script:

cosign verify --certificate-identity "https://github.com/organization/repository/.github/workflows/deploy.yml@refs/heads/main" --certificate-issuer "https://token.actions.githubusercontent.com" registry.example.com/app/service:v1.2.0

This command rigorously validates who signed the image, where the process took place, and whether the key used matches the organization's established security policy. If any parameter fails, execution is immediately halted, preventing vulnerable or unauthorized code from reaching the production environment.

Final Thoughts on Governance and Operational Maturity

Adopting continuous auditing based on SBOMs and digital signatures with Cosign elevates any technology organization's operational maturity to an advanced corporate level. The initial investment in configuring pipelines and adjusting admission policies pays off exponentially when a global security incident hits popular libraries, allowing the enterprise to identify and isolate the risk in minutes. Reliability engineering ceases to be a reactive firefighting effort and becomes a proactive discipline driven by mathematical evidence and transparent inventories.

The future of security in modern infrastructures points toward total trust automation, where no human element needs to manage secrets manually and every line of code has an inviolable audit trail. By combining standardized inventories with ephemeral identities and decentralized validation, teams build resilient systems capable of withstanding sophisticated supply chain attacks. The secret to success lies in the consistent application of these guidelines, turning security into a natural and non-negotiable byproduct of the development process.