Security Advisories for github.com/sigstore/gitsign in go
Low
about 1 year ago
gitsign may use incorrect Rekor entries during verification
go
github.com/sigstore/gitsign
Moderate
about 2 years ago
Gitsign's Rekor public keys fetched from upstream API instead of local TUF client.
go
github.com/sigstore/gitsign