diff --git a/images/mirror/Earthfile b/images/mirror/Earthfile
index 37d70548fd4a22a4a7cea847de2fccf40ee567df..d90f6e21a1b431df9b83ea11b78d11dd545856f3 100644
--- a/images/mirror/Earthfile
+++ b/images/mirror/Earthfile
@@ -29,7 +29,7 @@ fedora:
     DO +MIRROR --image=quay.io/fedora/fedora:39@sha256:490a2eb8c9ae75eb4f1cef7cd6bcd73c3fcc00e1a4822d3be592ff917b1353cf
 
 cosign:
-    DO +MIRROR --image=gcr.io/projectsigstore/cosign:v2.2.1
+    DO +MIRROR --image=gcr.io/projectsigstore/cosign:v2.2.2
     SAVE ARTIFACT /ko-app/cosign ./cosign
 
 # verify-distroless allows to use cosign to verify all mirrored distroless images against Google's build identity