Does this image get to deploy?

Pick what state the image is in, choose whether your deploy policy pins the expected signer or leaves it wide open, and run cosign verify. A valid signature is not enough — it has to be a signature by the signer you expected. Nothing is sent anywhere; the verify logic is re-implemented here.

Verify policy

cosign verify