This update for cosign fixes the following issues:
Updated to 1.10.1 (jsc#SLE-23879):
CVE-2022-35929: Fixed an issue where cosign verify-attestation --type
could report false positives when there was at least one attestation
with a valid signature and there were no attestations of the type
being verified (bsc#1202157).