Sign our container image with cosign

The ecosystem seems to be moving towards sigstore/cosign for signing artifacts. We should consider signing our container image with cosign.