cosign
Cosign is a go package for container Signing, verification and storage in an OCI registry.
Security Advisories for cosign in spack
Repackage
Moderate
over 2 years ago
Cosign malicious artifacts can cause machine-wide DoS
go
github.com/sigstore/cosign/v2, github.com/sigstore/cosign
Repackage
Moderate
over 2 years ago
Cosign malicious attachments can cause system-wide denial of service
go
github.com/sigstore/cosign/v2, github.com/sigstore/cosign
Repackage
Low
almost 3 years ago
Cosign vulnerable to possible endless data attack from attacker-controlled registry
go
github.com/sigstore/cosign/v2
Repackage
Moderate
almost 4 years ago
Cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature
go
github.com/sigstore/cosign
Repackage
High
about 4 years ago
cosign's `cosign verify-attestaton --type` can report a false positive if any attestation exists
go
github.com/sigstore/cosign
Repackage