7.5
CVSS V3
Status
Impact
The dependency github.com/sigstore/fulcio cannot be updated to v1.8.3 because the API has changed and cryptoutils.ValidatePubKey is now undefined; resolving this requires upgrading to cosign v3, which is not feasible as it introduces breaking API changes(e.g., sign.SignerFromKeyOpts is undefined) that would require significant refactoring of attestation.go and other signing-related code in vexctl.
Status