gpp_maybe Security update for cosign
SUSE-SLE-Module-Basesystem-15-SP4-2022-3486


This update for cosign fixes the following issues: Updated to version 1.12.0 (jsc#SLE-23879): - CVE-2022-36056: Fixed verify-blob could successfully verify an artifact when verification should have failed (bsc#1203430).

  • Release Date
    Oct 1 2022
  • References
    Bugzilla: 1203430
    CVEs: CVE-2022-36056
  • Type
    security
  • Severity
    important

cloud_download Downloads

Basesystem Module 15.4 ppc64le
  • Packages
    cosign
    Container Signing, Verification and Storage in an OCI registry
    1.12.0-150400.3.6.1 lock rpm lock src
Basesystem Module 15.4 aarch64
  • Packages
    cosign
    Container Signing, Verification and Storage in an OCI registry
    1.12.0-150400.3.6.1 lock rpm lock src
Basesystem Module 15.4 s390x
  • Packages
    cosign
    Container Signing, Verification and Storage in an OCI registry
    1.12.0-150400.3.6.1 lock rpm lock src
Basesystem Module 15.4 x86_64
  • Packages
    cosign
    Container Signing, Verification and Storage in an OCI registry
    1.12.0-150400.3.6.1 lock rpm lock src