Package
cosign-2
Component
github.com/chrismellard/docker-credential-acr-env
Latest update
Aliases
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
github.com/chrismellard/docker-credential-acr-env is no longer maintained: the pinned pseudo-version (82a0ddb, 2023-03-04) is the repository HEAD and no fixed release exists. The latest cosign releases (v2.6.5, v3.1.3) still depend on the vulnerable module, so no version bump or dependency pin can remediate this. Upstream cosign must migrate to a supported, remediated replacement; tracked in https://github.com/sigstore/cosign/issues/3913 with open migration PR https://github.com/sigstore/cosign/pull/4809.
Status
Impact
Govulncheck found vulnerable symbols in Go binary at usr/bin/cosign.
Status