SecurityContainer Image Hardening: Distroless, Multi-Stage and Cosign Signing
A good production image is small, non-root, has no shell, is scanned and is signed. This article covers Docker/OCI image hardening techniques together with a Cosign keyless signing workflow using GitHub OIDC.