cloudbeat-9.0
Chainguard
7.5
CVSS V3
Status
Impact
Vulnerability is present due to a transitive dependency on github.com/sigstore/timestamp-authority@v1.2.2. The fix for this vulnerability requires advancing the major version to github.com/sigstore/timestamp-authority@v2.0.3, which is not possible via a go.mod 'replace'. The direct dependencies that introduce this transitive dependency do not currently have releases that pin to the remediated timestamp-authority@v2.0.3, so we cannot remediate this through module bumps.
Status