sequoia-git
Activity
- Latest release
- 4mo ago
- Total releases
- 6
- Cadence
- ~2 months
- Last 12 months
- 2
Details
- License
- LGPL-2.0-or-later
- First release
- Sep 19, 2023
| Version | Released | |
|---|---|---|
0.6.0
unknown
|
0.6.0
unknown
Dependencies (25)
+ 17 more |
|
0.5.0
unknown
1 CVE
GHSA-g27r-r6ph-vf5r
RUSTSEC-2026-0109
May 04, 2026
sequoia-git has broken hard revocation handling
Low
Network
High
High
Before An attacker could nevertheless exploit this flaw as follows. Consider Alice and Bob who maintain a project together. If Bob's
certificate is compromised and Bob issues a hard revocation, Alice can add it to the project's signing policy. An attacker who has
access to Bob's key can then create a merge request that strips the hard revocation. If Alice merges Bob's merge request, then
the latest commit will not carry the hard revocation, and Note: for this attack to be successful, Alice needs to be tricked into merging the malicious MR. If Alice is reviewing MRs, then she is likely to notice changes to the signing policy. Reported-by: Hassan Sheet Fixed in
0.6.0
References Updated May 06, 2026 · Source: OSV.dev |
0.5.0
unknown
Dependencies (25)
+ 17 more |
|
0.4.0
unknown
1 CVE
GHSA-g27r-r6ph-vf5r
RUSTSEC-2026-0109
May 04, 2026
sequoia-git has broken hard revocation handling
Low
Network
High
High
Before An attacker could nevertheless exploit this flaw as follows. Consider Alice and Bob who maintain a project together. If Bob's
certificate is compromised and Bob issues a hard revocation, Alice can add it to the project's signing policy. An attacker who has
access to Bob's key can then create a merge request that strips the hard revocation. If Alice merges Bob's merge request, then
the latest commit will not carry the hard revocation, and Note: for this attack to be successful, Alice needs to be tricked into merging the malicious MR. If Alice is reviewing MRs, then she is likely to notice changes to the signing policy. Reported-by: Hassan Sheet Fixed in
0.6.0
References Updated May 06, 2026 · Source: OSV.dev |
0.4.0
unknown
Dependencies (26)
+ 18 more |
|
0.3.0
unknown
1 CVE
GHSA-g27r-r6ph-vf5r
RUSTSEC-2026-0109
May 04, 2026
sequoia-git has broken hard revocation handling
Low
Network
High
High
Before An attacker could nevertheless exploit this flaw as follows. Consider Alice and Bob who maintain a project together. If Bob's
certificate is compromised and Bob issues a hard revocation, Alice can add it to the project's signing policy. An attacker who has
access to Bob's key can then create a merge request that strips the hard revocation. If Alice merges Bob's merge request, then
the latest commit will not carry the hard revocation, and Note: for this attack to be successful, Alice needs to be tricked into merging the malicious MR. If Alice is reviewing MRs, then she is likely to notice changes to the signing policy. Reported-by: Hassan Sheet Fixed in
0.6.0
References Updated May 06, 2026 · Source: OSV.dev |
0.3.0
unknown
Dependencies (26)
+ 18 more |
|
0.2.0
unknown
1 CVE
GHSA-g27r-r6ph-vf5r
RUSTSEC-2026-0109
May 04, 2026
sequoia-git has broken hard revocation handling
Low
Network
High
High
Before An attacker could nevertheless exploit this flaw as follows. Consider Alice and Bob who maintain a project together. If Bob's
certificate is compromised and Bob issues a hard revocation, Alice can add it to the project's signing policy. An attacker who has
access to Bob's key can then create a merge request that strips the hard revocation. If Alice merges Bob's merge request, then
the latest commit will not carry the hard revocation, and Note: for this attack to be successful, Alice needs to be tricked into merging the malicious MR. If Alice is reviewing MRs, then she is likely to notice changes to the signing policy. Reported-by: Hassan Sheet Fixed in
0.6.0
References Updated May 06, 2026 · Source: OSV.dev |
0.2.0
unknown
Dependencies (25)
+ 17 more |
|
0.1.0
unknown
1 CVE
GHSA-g27r-r6ph-vf5r
RUSTSEC-2026-0109
May 04, 2026
sequoia-git has broken hard revocation handling
Low
Network
High
High
Before An attacker could nevertheless exploit this flaw as follows. Consider Alice and Bob who maintain a project together. If Bob's
certificate is compromised and Bob issues a hard revocation, Alice can add it to the project's signing policy. An attacker who has
access to Bob's key can then create a merge request that strips the hard revocation. If Alice merges Bob's merge request, then
the latest commit will not carry the hard revocation, and Note: for this attack to be successful, Alice needs to be tricked into merging the malicious MR. If Alice is reviewing MRs, then she is likely to notice changes to the signing policy. Reported-by: Hassan Sheet Fixed in
0.6.0
References Updated May 06, 2026 · Source: OSV.dev |
0.1.0
unknown
Dependencies (20)
+ 12 more |