These are all security issues fixed in the cosign-2.5.0-1.1 package on the GA media of openSUSE Tumbleweed.
{ "binaries": [ { "cosign-zsh-completion": "2.5.0-1.1", "cosign": "2.5.0-1.1", "cosign-bash-completion": "2.5.0-1.1", "cosign-fish-completion": "2.5.0-1.1" } ] }