Skip to main content

ghcr.io/sigstore/cosign/cosign:v3.0.6

Base OS: debian 12.1328 vulnerabilities fixed
Patched Image
ghcr.io/verity-org/sigstore/cosign:v3.0.6
SignedSLSA L3SBOMRekor
Verify this artifact
Cosign signature
cosign verify \
  --certificate-identity-regexp "https://github.com/verity-org/verity/.github/workflows/" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  ghcr.io/verity-org/sigstore/cosign:v3.0.6
Build provenance
gh attestation verify \
  oci://ghcr.io/verity-org/sigstore/cosign:v3.0.6 \
  --owner verity-org

Before patching

Found 50 vulnerabilities in the original image. 28 fixed by Copa. 22 remaining after patching.

27 HIGH20 MEDIUM1 LOW2 UNKNOWN

Fix available — pending patch

These vulnerabilities have upstream fixes but could not be automatically patched. Manual remediation may be required.

Awaiting upstream fix

No fix is available yet for these vulnerabilities. They can be suppressed in your compliance tooling until an upstream fix is released.

Original image reference
ghcr.io/sigstore/cosign/cosign:v3.0.6