diff --git a/images/mirror/Earthfile b/images/mirror/Earthfile
index 51469330fd6947b532438be00771624a1ae62907..95212d91fa35f057c755ac135c9dfb2f71f22d39 100644
--- a/images/mirror/Earthfile
+++ b/images/mirror/Earthfile
@@ -29,7 +29,7 @@ fedora:
     DO +MIRROR --image=quay.io/fedora/fedora:39@sha256:490a2eb8c9ae75eb4f1cef7cd6bcd73c3fcc00e1a4822d3be592ff917b1353cf
 
 cosign:
-    DO +MIRROR --image=gcr.io/projectsigstore/cosign:v2.2.2
+    DO +MIRROR --image=gcr.io/projectsigstore/cosign:v2.2.3
     SAVE ARTIFACT /ko-app/cosign ./cosign
 
 # verify-distroless allows to use cosign to verify all mirrored distroless images against Google's build identity