Closed
Description
Description
With #3796, we added support to cosign for using trusted roots when verifying protobuf bundles. If you leave off the trusted root, we assuming the public good instance, and we fetch the trusted root via TUF with a network request. This was confusing to some users, so we should add a log message explaining what's going on.