ratify-fips
Chainguard
7.5
CVSS V3
Status
Impact
timestamp-authority is a transitive dependency brought in by cosign. Upgrading to the cosign version (v3.0.3) that includes the fixed timestamp-authority causes build failures. Upstream maintainers will need to update the version of cosign included in ratify.
Status