/post/devops-sigstore-cosign-slsa/
https://blog.stephane-robert.info/docs/securiser/supply-chain/cosign/