Skip to content

cosign's `cosign verify-attestaton --type` can report a false positive if any attestation exists

High severity GitHub Reviewed Published Aug 4, 2022 in sigstore/cosign • Updated Jan 30, 2023

No open alerts for this advisory

Give feedback on Dependabot alerts