Package
cloudbeat-9.2
Component
github.com/sigstore/cosign/v2
Latest update
Fixed version
9.2.8-r11
3.7
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
9.2.8-r11Status
Impact
The fix for this vulnerability is available only in the renamed github.com/sigstore/cosign/v3 module (v3.0.5 and later). The package's runtime code imports the cosign/v2 module, which has no upstream fix; reaching the fix requires the upstream migration from the v2 module path to v3, which has not landed on this release stream. Remediation is pending that upstream module migration.
Status