Skip to content

Gitsign's Rekor public keys fetched from upstream API instead of local TUF client.

Moderate severity GitHub Reviewed Published Nov 10, 2023 in sigstore/gitsign • Updated Nov 14, 2023

No open alerts for this advisory

Give feedback on Dependabot alerts