Skip to content

Conversation

@dnegreira
Copy link
Member

Update advisories for CVE-2025-66564 and CVE-2025-66506

github.com/sigstore/fulcio is a direct dependency of gitsign

github.com/sigstore/timestamp-authority is a transitive dependency
pulled in by github.com/sigstore/cosign.

Any attempts to bump github.com/sigstore/fulcio or
github.com/sigstore/timestamp-authority result in build failures.

gitsign currently has an open PR in order to bump fulcio to v1.8.3 [1]

The bump has already happened in the upstream sigstore v3.0.3 version. [2]

We need to wait for upstream to cut a new release with the new software
versions.

[1] sigstore/gitsign#730
[2] sigstore/cosign@5a60384

Signed-off-by: David Negreira [email protected]

Update advisories for CVE-2025-66564 and CVE-2025-66506

github.com/sigstore/fulcio is a direct dependency of gitsign

github.com/sigstore/timestamp-authority is a transitive dependency
pulled in by github.com/sigstore/cosign.

Any attempts to bump github.com/sigstore/fulcio or
github.com/sigstore/timestamp-authority result in build failures.

gitsign currently has an open PR in order to bump fulcio to v1.8.3 [1]

The bump has already happened in the upstream sigstore v3.0.3 version. [2]

We need to wait for upstream to cut a new release with the new software
versions.

[1] sigstore/gitsign#730
[2] sigstore/cosign@5a60384

Signed-off-by: David Negreira <[email protected]>
@dnegreira dnegreira added this pull request to the merge queue Dec 15, 2025
Merged via the queue into wolfi-dev:main with commit f53b60e Dec 15, 2025
4 checks passed
@dnegreira dnegreira deleted the gitsign-GHSA-4qg8-fj49-pxjh-GHSA-f83f-xpx7-ffpw branch December 15, 2025 16:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants