Package
cg
Component
github.com/sigstore/fulcio
Latest update
Fixed version
0.2.193-r1
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
0.2.193-r1Status
Impact
We tried remediating this CVE by using a newer, fixed version of the go module, however the vulnerable version still gets pulled by transitive dependencies at build time. The different upstreams, for the main package and the transitive dependencies, should update and release fixed versions before we can consider this CVE fixed.
Status
Status