Security update for trivy

This update for trivy fixes the following issues:

Update vendor.tar to address:

* boo#1278624, CVE-2026-56855,CVE-2026-56854,CVE-2026-78662:
golang.org/x/crypto/ssh: authentication bypass and deadlocks
in the crypto/ssh library
* boo#1280111, CVE-2026-53495: containerd: CRI ExecSync Goroutine
Leak Leads to Node-Level Denial of Service

Update vendor to address:

* boo#1279395, CVE-2026-84304: trivy: github.com/grpc/grpc-go:
heap memory exhaustion via HTTP/2 DATA frame
* boo#1279392, CVE-2026-84445: trivy: google.golang.org/grpc: DoS
via crash due to missing `:authority` and `Host` headers
* boo#1279390, CVE-2026-84303: trivy: github.com/grpc/grpc-go:
xDS RBAC HTTP filter implementation issue allows for bypass
of authorization

Update to version 0.74.0 (boo#1278702, CVE-2026-50163,
boo#1278002, CVE-2026-37236,
boo#1278624, CVE-2026-56855,CVE-2026-56854,CVE-2026-78662):
CVE-2026-72817,CVE-2026-72815,CVE-2026-72816,
boo#1276745, CVE-2026-41178,
boo#1258543, CVE-2026-24122).

Fixed bugs
bnc#1278624
VUL-0: CVE-2026-56855,CVE-2026-56854,CVE-2026-78662: trivy: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library
bnc#1279390
VUL-0: CVE-2026-84303: trivy: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches
bnc#1278702
VUL-0: CVE-2026-50163: trivy: oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks
bnc#1280111
VUL-0: CVE-2026-53495: trivy: containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
bnc#1279392
VUL-0: CVE-2026-84445: trivy: google.golang.org/grpc: DoS via crash due to missing `:authority` and `Host` headers in gRPC-Go xDS servers
bnc#1279395
VUL-0: CVE-2026-84304: trivy: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation
bnc#1278002
VUL-0: CVE-2026-37236: trivy: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST request through the X-HTTP-Method-Override header and bypass established access control
bnc#1276745
VUL-0: CVE-2026-41178: trivy: go.opentelemetry.io/otel/baggage, go.opentelemetry.io/otel/propagation: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs
bnc#1258543
VUL-0: CVE-2026-24122: trivy: github.com/sigstore/cosign/v2/pkg/cosign: improper validation of certificates that outlive expired CA certificates
Selected Binaries
openSUSE Build Service is sponsored by