7.1
CVSS V3
PolicyController before 0.2.1 may bypass attestation verification
PolicyController will report a false positive, resulting in an admission when it should not be admitted when:
Users should upgrade to cosign version 0.2.1 or greater for a patch. There are no known workarounds at this time.