For highly regulated clients there's an interest in the DB image being signed. This could be done on GHCR with cosign.