This update for cockpit-packages fixes the following issue:
Update cockpit-packages to version 4:
CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character
that doesn't appear in the test string (bsc#1258641).