GO-2026-4529 : Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign
The highest tagged major version is
v3 .
Discover Packages
github.com/sigstore/cosign/v2
internal
pkg
oci
remote
package
Version:
v2.6.3
Opens a new window with list of versions in this module.
Published: Apr 6, 2026
License: Apache-2.0
Opens a new window with license information.
Imports: 1
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation
Documentation
¶
ArtifactType converts a attachment name (sig/sbom/att/etc.) into a valid artifactType (OCI 1.1+).
Source Files
¶
Click to show internal directories.
Click to hide internal directories.