GO-2024-3252: gitsign may use incorrect Rekor entries during verification in github.com/sigstore/gitsign
package
Version:
v0.8.1
Opens a new window with list of versions in this module.
Published: Feb 5, 2024
License: Apache-2.0
Opens a new window with license information.
Imports: 3
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation
¶
Package initialize inits the TUF root for the tool.
This is intended to replicate the behavior of `gitsign initialize`.
Source Files
¶
Click to show internal directories.
Click to hide internal directories.