SUSE-RU-2026:3322-1: moderate: Recommended update for cosign

SLE-UPDATES null at suse.de
Tue Jul 28 12:43:27 UTC 2026


# Recommended update for cosign

Announcement ID: SUSE-RU-2026:3322-1  
Release Date: 2026-07-28T06:11:46Z  
Rating: moderate  
References:

  
Affected Products:

  * Basesystem Module 15-SP7
  * openSUSE Leap 15.4
  * SUSE Linux Enterprise Desktop 15 SP7
  * SUSE Linux Enterprise High Performance Computing 15 SP4
  * SUSE Linux Enterprise High Performance Computing 15 SP5
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
  * SUSE Linux Enterprise Real Time 15 SP7
  * SUSE Linux Enterprise Server 15 SP4
  * SUSE Linux Enterprise Server 15 SP4 LTSS
  * SUSE Linux Enterprise Server 15 SP5
  * SUSE Linux Enterprise Server 15 SP5 LTSS
  * SUSE Linux Enterprise Server 15 SP6
  * SUSE Linux Enterprise Server 15 SP6 LTSS
  * SUSE Linux Enterprise Server 15 SP7
  * SUSE Linux Enterprise Server for SAP Applications 15 SP4
  * SUSE Linux Enterprise Server for SAP Applications 15 SP5
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6
  * SUSE Linux Enterprise Server for SAP Applications 15 SP7

  
  
An update that can now be installed.

## Description:

This update for cosign fixes the following issues:

  * updated to version 3.1.2:
    * Deprecate --payload for sign and verify commands
    * docs: add OVHcloud KMS in available external plugins
    * Add insecure registry flag to ko publish in kind-verify-attestation workflow 
    * Deprecate --output-attestation
    * Add bundle inspect command
    * Guard against empty certificate PEM in mutate.Signature
    * fix(download): Validate predicate type for new bundle format
    * Skip nil subject entries in IntotoSubjectClaimVerifier
    * Fix Makefile: fall back to "unknown" version info when built outside a git repo
    * fix(verify): skip identity validation for security keys
    * fix: include artifactType in OCI 1.1 signature referrer manifest
    * Allow attestation download to handle both bundle types
    * Fix panic in dockerfile verify on malformed FROM lines
    * fix(release): restore signing-step auth and fail on image signing errors
    * feat(signing-config): add --base-config flag to override services from base config
    * fix: pass NewBundleFormat to KeyOpts in sign command
    * fix: ignore build stage references in dockerfile verify
    * fix: allow '=' in annotation values
    * Remove unused policy evaluation code
    * Remove unused signing code
    * Remove unused OCI code
    * Remove unused ephemeral signer
    * feat: improve verify flag shell completions
    * docs: fix Short style and add Example fields to piv-tool subcommands
    * docs: add Example fields to env and bundle create commands
    * docs: fix Short style and add Example fields to pkcs11-tool subcommands

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server 15 SP4 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3322=1

  * SUSE Linux Enterprise Server 15 SP5 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3322=1

  * SUSE Linux Enterprise Server for SAP Applications 15 SP6  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3322=1

  * openSUSE Leap 15.4  
    zypper in -t patch SUSE-2026-3322=1

  * SUSE Linux Enterprise Server for SAP Applications 15 SP5  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3322=1

  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3322=1

  * SUSE Linux Enterprise Server 15 SP6 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3322=1

  * SUSE Linux Enterprise Server for SAP Applications 15 SP4  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3322=1

  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3322=1

  * Basesystem Module 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3322=1

  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3322=1

  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3322=1

## Package List:

  * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
    * cosign-3.1.2-150400.3.50.1
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
    x86_64)
    * cosign-3.1.2-150400.3.50.1
  * Basesystem Module 15-SP7 (noarch)
    * cosign-bash-completion-3.1.2-150400.3.50.1
    * cosign-zsh-completion-3.1.2-150400.3.50.1
  * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
    * cosign-3.1.2-150400.3.50.1
    * cosign-debuginfo-3.1.2-150400.3.50.1
  * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
    * cosign-3.1.2-150400.3.50.1
    * cosign-debuginfo-3.1.2-150400.3.50.1
  * openSUSE Leap 15.4 (noarch)
    * cosign-bash-completion-3.1.2-150400.3.50.1
    * cosign-zsh-completion-3.1.2-150400.3.50.1
    * cosign-fish-completion-3.1.2-150400.3.50.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
    * cosign-3.1.2-150400.3.50.1
    * cosign-debuginfo-3.1.2-150400.3.50.1
  * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
    * cosign-3.1.2-150400.3.50.1
    * cosign-debuginfo-3.1.2-150400.3.50.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
    * cosign-3.1.2-150400.3.50.1
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
    x86_64)
    * cosign-3.1.2-150400.3.50.1
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
    x86_64)
    * cosign-3.1.2-150400.3.50.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
    * cosign-3.1.2-150400.3.50.1
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
    x86_64)
    * cosign-3.1.2-150400.3.50.1
  * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
    * cosign-3.1.2-150400.3.50.1

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260728/e017b59a/attachment.htm>


More information about the sle-updates mailing list