gpp_maybe Security update for cosign
SUSE-SLE-Module-Basesystem-15-SP4-2022-2877


This update for cosign fixes the following issues: - Updated to 1.10.1 (jsc#SLE-23879): - CVE-2022-35929: Fixed an issue where cosign verify-attestation --type could report false positives when there was at least one attestation with a valid signature and there were no attestations of the type being verified (bsc#1202157).

  • Release Date
    Aug 23 2022
  • References
    Bugzilla: 1202157
    CVEs: CVE-2022-35929
  • Type
    security
  • Severity
    important

cloud_download Downloads

Basesystem Module 15.4 s390x
  • Packages
    cosign
    Container Signing, Verification and Storage in an OCI registry
    1.10.1-150400.3.3.1 lock rpm lock src
Basesystem Module 15.4 x86_64
  • Packages
    cosign
    Container Signing, Verification and Storage in an OCI registry
    1.10.1-150400.3.3.1 lock rpm lock src
Basesystem Module 15.4 ppc64le
  • Packages
    cosign
    Container Signing, Verification and Storage in an OCI registry
    1.10.1-150400.3.3.1 lock rpm lock src
Basesystem Module 15.4 aarch64
  • Packages
    cosign
    Container Signing, Verification and Storage in an OCI registry
    1.10.1-150400.3.3.1 lock rpm lock src