Skip to content

Cosign verification accepts any valid Rekor entry under certain conditions

Moderate severity GitHub Reviewed Published Jan 9, 2026 in sigstore/cosign • Updated Jan 13, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts