Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
SingularityCE isn't affected by this. OCI-SIF cosign compatible signature support in SingularityCE is limited, and doesn't include transaction log (Rekor) functionality. See: https://docs.sylabs.io/guides/4.3/user-guide/signNverify.html#limitations