cosign-fixtures is a tool to generate valid and invalid cosign signed artifacts
This is used to test the Cosign validator implementation.
This could be dynamically executed on every test but cryptographic operations
are costly and this would make things a bit less debuggable.