Update cosign documentation for attestation parsing
Cosign Documentation Updates
We should update our Cosign documentation to add instructions for how to parse attestations out of registry images. The following command cycles through all found attestations, decodes them, and stores them in separate files on disk:
count=0;
for att in $(cosign \
download \
attestation \
harbor-ib-zelda.staging.dso.mil/ironbank/opensource/thanos/thanos@sha256:a742c6d48a539163d7ccc7ee53ac114cd70cd92cedeb88956f7462dabb704bb4 \
| jq .payload -r); do
count=$((count+1)); echo $att | base64 --decode | jq > "att-$count.json";
done
Edited by Tim Seagren