Package
cloudbeat-fips-9.0
Component
github.com/sigstore/timestamp-authority
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
Vulnerability is present due to a transitive dependency on github.com/sigstore/timestamp-authority@v1.2.2. The fix for this vulnerability requires advancing the major version to github.com/sigstore/timestamp-authority@v2.0.3, which is not possible via a go.mod 'replace'. The direct dependencies that introduce this transitive dependency do not currently have releases that pin to the remediated timestamp-authority@v2.0.3, so we cannot remediate this through module bumps.
Status
Status