Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package cosign for openSUSE:Factory checked in at 2026-02-20 17:42:35 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/cosign (Old) and /work/SRC/openSUSE:Factory/.cosign.new.1977 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "cosign" Fri Feb 20 17:42:35 2026 rev:32 rq:1333995 version:3.0.4 Changes: -------- --- /work/SRC/openSUSE:Factory/cosign/cosign.changes 2026-02-12 17:29:33.452865874 +0100 +++ /work/SRC/openSUSE:Factory/.cosign.new.1977/cosign.changes 2026-02-20 17:50:38.667564978 +0100 @@ -4,0 +5,4 @@ + * CVE-2025-11065: Fixed github.com/go-viper/mapstructure/v2: sensitive + Information leak in logs (bsc#1250620) + * CVE-2026-22703: Fixed that cosign verification accepts any valid + Rekor entry under certain conditions (bsc#1256496) @@ -48,0 +53,2 @@ + * CVE-2025-58181: Fixed golang.org/x/crypto/ssh: invalidated number + of mechanisms can cause unbounded memory consumption (bsc#1253913) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------
