github.com/sigstore/cosign

govv1.13.6

Code signing and transparency for containers and binaries

License Apache-2.0permissive39 versions248 maintainers0 deps5,837 weekly dl
sigstore/cosign
42
/ 100
Health
safe to use

github.com/sigstore/[email protected] is safe to use (health: 42/100)

Update to >= 3.0.5 to fix known vulnerabilities

Health breakdown0 – 100
0/25
maintenance
6/20
popularity
19/25
security
12/15
maturity
5/15
community
Vulnerabilities
10
3 medium7 low
Advisories (10)
SeverityIDSummaryFixed in
mediumBIT-cosign-2024-29902Cosign malicious attachments can cause system-wide denial of service2.2.4
mediumBIT-cosign-2024-29903Cosign malicious artifacts can cause machine-wide DoS2.2.4
lowBIT-cosign-2023-46737Cosign vulnerable to possible endless data attack from attacker-controlled registry2.2.1
mediumBIT-cosign-2026-39395Cosign's verify-blob-attestation reports false positive when payload parsing fails2.6.3
lowBIT-cosign-2026-24122Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped3.0.5
unknownBIT-cosign-2023-46737Denial of service attack from remote registry in github.com/sigstore/cosign2.2.1
unknownBIT-cosign-2024-29902Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign2.2.4
unknownBIT-cosign-2024-29903Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign2.2.4
unknownBIT-cosign-2026-22703Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign3.0.4
unknownBIT-cosign-2026-24122Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign3.0.5

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/go/github.com/sigstore/cosign

Last updated · 2024-03-21T22:30:20Z

github.com/sigstore/cosign — Health Score 42/100 | DepScope