Skip to content

Upgrade cosign installer to v4.1.2 and pin cosign version#83

Merged
oschwartz10612 merged 1 commit into
mainfrom
github-action-cosign
May 16, 2026
Merged

Upgrade cosign installer to v4.1.2 and pin cosign version#83
oschwartz10612 merged 1 commit into
mainfrom
github-action-cosign

Conversation

@marcschaeferger
Copy link
Copy Markdown
Member

Description

Updates the Cosign installer workflow usage and explicitly pins the installed Cosign binary to v3.0.6.

Why

Cosign versions below 3.0.6 are affected by CVE-2026-39395. While this workflow was not explicitly pinned to an older vulnerable Cosign binary, the installed Cosign version was implicit and therefore less deterministic.

Changes

References

Updated cosign installer to version 4.1.2 and specified cosign release version 3.0.6.
@oschwartz10612 oschwartz10612 merged commit 65bb3fc into main May 16, 2026
1 check passed
@oschwartz10612 oschwartz10612 deleted the github-action-cosign branch May 16, 2026 21:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants