Affected by GO-2023-2332
and 1 other vulnerabilities
GO-2023-2332: Gitsign's Rekor public keys fetched from upstream API instead of local TUF client. in github.com/sigstore/gitsign
GO-2024-3252: gitsign may use incorrect Rekor entries during verification in github.com/sigstore/gitsign
package
Version:
v0.7.1
Opens a new window with list of versions in this module.
Published: May 22, 2023
License: Apache-2.0
Opens a new window with license information.
Imports: 19
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation
¶
Source Files
¶
Click to show internal directories.
Click to hide internal directories.