Package
reports-server
Component
github.com/sigstore/cosign/v2
Latest update
4.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
github.com/sigstore/cosign/v2@v2.2.4 is a transitive dependency vendored via k8s-manifest-sigstore. reports-server does not perform cosign signature/attestation verification. govulncheck binary-mode analysis of the shipped reports-server binary confirms the vulnerable cosign symbols are not reachable (dead-code-eliminated). The vulnerable code path is never executed.
Status