github.com/notaryproject/notation-go
Activity
- Latest release
- Apr 18, 2025
- Total releases
- 26
- Cadence
- ~35 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Oct 19, 2021
| Version | Released | |
|---|---|---|
v1.3.2
patch
|
v1.3.2
patch
Dependencies (10)
+ 2 more |
|
v1.3.1
patch
|
v1.3.1
patch
Dependencies (10)
+ 2 more |
|
v1.3.0
minor
|
v1.3.0
minor
Dependencies (10)
+ 2 more |
|
v1.3.0-rc.2
pre
|
v1.3.0-rc.2
pre
Dependencies (10)
+ 2 more |
|
v1.3.0-rc.1
pre
2 CVEs
CVE-2024-51491
GO-2025-3382
GHSA-qjh3-4j3h-vmwp
Jan 14, 2025
notation-go has an OS error when setting CRL cache leads to denial of signature verification in github.com/notaryproject/notation-go notation-go has an OS error when setting CRL cache leads to denial of signature verification in github.com/notaryproject/notation-go Fixed in
1.3.0-rc.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-56138
GO-2025-3381
GHSA-45v3-38pc-874v
Jan 14, 2025
notation-go's timestamp signature generation lacks certificate revocation check in github.com/notaryproject/notation-go notation-go's timestamp signature generation lacks certificate revocation check in github.com/notaryproject/notation-go Fixed in
1.3.0-rc.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.0-rc.1
pre
Dependencies (10)
+ 2 more |
|
v1.1.2
patch
|
v1.1.2
patch
Dependencies (9)
+ 1 more |
|
v1.2.1
patch
1 CVE
CVE-2024-56138
GO-2025-3381
GHSA-45v3-38pc-874v
Jan 14, 2025
notation-go's timestamp signature generation lacks certificate revocation check in github.com/notaryproject/notation-go notation-go's timestamp signature generation lacks certificate revocation check in github.com/notaryproject/notation-go Fixed in
1.3.0-rc.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.1
patch
Dependencies (10)
+ 2 more |
|
v1.2.0
minor
1 CVE
CVE-2024-56138
GO-2025-3381
GHSA-45v3-38pc-874v
Jan 14, 2025
notation-go's timestamp signature generation lacks certificate revocation check in github.com/notaryproject/notation-go notation-go's timestamp signature generation lacks certificate revocation check in github.com/notaryproject/notation-go Fixed in
1.3.0-rc.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (10)
+ 2 more |
|
v1.2.0-rc.1
pre
1 CVE
CVE-2024-56138
GO-2025-3381
GHSA-45v3-38pc-874v
Jan 14, 2025
notation-go's timestamp signature generation lacks certificate revocation check in github.com/notaryproject/notation-go notation-go's timestamp signature generation lacks certificate revocation check in github.com/notaryproject/notation-go Fixed in
1.3.0-rc.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.0-rc.1
pre
Dependencies (10)
+ 2 more |
|
v1.2.0-beta.1
pre
1 CVE
CVE-2024-56138
GO-2025-3381
GHSA-45v3-38pc-874v
Jan 14, 2025
notation-go's timestamp signature generation lacks certificate revocation check in github.com/notaryproject/notation-go notation-go's timestamp signature generation lacks certificate revocation check in github.com/notaryproject/notation-go Fixed in
1.3.0-rc.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.0-beta.1
pre
Dependencies (10)
+ 2 more |
|
v1.1.1
patch
|
v1.1.1
patch
Dependencies (9)
+ 1 more |
|
v1.1.0
minor
|
v1.1.0
minor
Dependencies (8)
|
|
v1.0.1
patch
|
v1.0.1
patch
Dependencies (8)
|
|
v1.0.0
initial
|
v1.0.0
initial
Dependencies (8)
|
|
v1.0.0-rc.6
pre
|
v1.0.0-rc.6
pre
Dependencies (8)
|
|
v1.0.0-rc.5
pre
1 CVE
CVE-2023-33959
GO-2023-1832
GHSA-xhg5-42rf-296r
Jun 26, 2023
Verification bypass in github.com/notaryproject/notation-go An attacker who controls or compromises a registry can lead a user to verify the wrong artifact. Fixed in
1.0.0-rc.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.0-rc.5
pre
Dependencies (8)
|
|
v1.0.0-rc.4
pre
1 CVE
CVE-2023-33959
GO-2023-1832
GHSA-xhg5-42rf-296r
Jun 26, 2023
Verification bypass in github.com/notaryproject/notation-go An attacker who controls or compromises a registry can lead a user to verify the wrong artifact. Fixed in
1.0.0-rc.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.0-rc.4
pre
Dependencies (8)
|
|
v1.0.0-rc.3
pre
1 CVE
CVE-2023-33959
GO-2023-1832
GHSA-xhg5-42rf-296r
Jun 26, 2023
Verification bypass in github.com/notaryproject/notation-go An attacker who controls or compromises a registry can lead a user to verify the wrong artifact. Fixed in
1.0.0-rc.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.0-rc.3
pre
Dependencies (7)
|
|
v1.0.0-rc.2
pre
2 CVEs
CVE-2023-25656
GO-2023-1589
GHSA-87x9-7grx-m28v
Jul 11, 2023
Denial of service from memory exhaustion in github.com/notaryproject/notation-go Parsing PKIX distinguished names containing the string "=#" can cause excessive memory consumption. Fixed in
1.0.0-rc.3
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-33959
GO-2023-1832
GHSA-xhg5-42rf-296r
Jun 26, 2023
Verification bypass in github.com/notaryproject/notation-go An attacker who controls or compromises a registry can lead a user to verify the wrong artifact. Fixed in
1.0.0-rc.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.0-rc.2
pre
Dependencies (7)
|
|
v1.0.0-rc.1
pre
2 CVEs
CVE-2023-25656
GO-2023-1589
GHSA-87x9-7grx-m28v
Jul 11, 2023
Denial of service from memory exhaustion in github.com/notaryproject/notation-go Parsing PKIX distinguished names containing the string "=#" can cause excessive memory consumption. Fixed in
1.0.0-rc.3
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-33959
GO-2023-1832
GHSA-xhg5-42rf-296r
Jun 26, 2023
Verification bypass in github.com/notaryproject/notation-go An attacker who controls or compromises a registry can lead a user to verify the wrong artifact. Fixed in
1.0.0-rc.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.0-rc.1
pre
Dependencies (6)
|
|
v0.12.0-beta.1
pre
2 CVEs
CVE-2023-25656
GO-2023-1589
GHSA-87x9-7grx-m28v
Jul 11, 2023
Denial of service from memory exhaustion in github.com/notaryproject/notation-go Parsing PKIX distinguished names containing the string "=#" can cause excessive memory consumption. Fixed in
1.0.0-rc.3
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-33959
GO-2023-1832
GHSA-xhg5-42rf-296r
Jun 26, 2023
Verification bypass in github.com/notaryproject/notation-go An attacker who controls or compromises a registry can lead a user to verify the wrong artifact. Fixed in
1.0.0-rc.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.12.0-beta.1
pre
Dependencies (7)
|
|
v0.11.0-alpha.4
pre
2 CVEs
CVE-2023-25656
GO-2023-1589
GHSA-87x9-7grx-m28v
Jul 11, 2023
Denial of service from memory exhaustion in github.com/notaryproject/notation-go Parsing PKIX distinguished names containing the string "=#" can cause excessive memory consumption. Fixed in
1.0.0-rc.3
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-33959
GO-2023-1832
GHSA-xhg5-42rf-296r
Jun 26, 2023
Verification bypass in github.com/notaryproject/notation-go An attacker who controls or compromises a registry can lead a user to verify the wrong artifact. Fixed in
1.0.0-rc.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.11.0-alpha.4
pre
Dependencies (7)
|
|
v0.10.0-alpha.3
pre
2 CVEs
CVE-2023-25656
GO-2023-1589
GHSA-87x9-7grx-m28v
Jul 11, 2023
Denial of service from memory exhaustion in github.com/notaryproject/notation-go Parsing PKIX distinguished names containing the string "=#" can cause excessive memory consumption. Fixed in
1.0.0-rc.3
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-33959
GO-2023-1832
GHSA-xhg5-42rf-296r
Jun 26, 2023
Verification bypass in github.com/notaryproject/notation-go An attacker who controls or compromises a registry can lead a user to verify the wrong artifact. Fixed in
1.0.0-rc.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.10.0-alpha.3
pre
Dependencies (7)
|
|
v0.9.0-alpha.1
pre
2 CVEs
CVE-2023-25656
GO-2023-1589
GHSA-87x9-7grx-m28v
Jul 11, 2023
Denial of service from memory exhaustion in github.com/notaryproject/notation-go Parsing PKIX distinguished names containing the string "=#" can cause excessive memory consumption. Fixed in
1.0.0-rc.3
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-33959
GO-2023-1832
GHSA-xhg5-42rf-296r
Jun 26, 2023
Verification bypass in github.com/notaryproject/notation-go An attacker who controls or compromises a registry can lead a user to verify the wrong artifact. Fixed in
1.0.0-rc.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.9.0-alpha.1
pre
Dependencies (3)
|
|
v0.8.0-alpha.1
pre
2 CVEs
CVE-2023-25656
GO-2023-1589
GHSA-87x9-7grx-m28v
Jul 11, 2023
Denial of service from memory exhaustion in github.com/notaryproject/notation-go Parsing PKIX distinguished names containing the string "=#" can cause excessive memory consumption. Fixed in
1.0.0-rc.3
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-33959
GO-2023-1832
GHSA-xhg5-42rf-296r
Jun 26, 2023
Verification bypass in github.com/notaryproject/notation-go An attacker who controls or compromises a registry can lead a user to verify the wrong artifact. Fixed in
1.0.0-rc.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.8.0-alpha.1
pre
Dependencies (2)
|
|
v0.7.0-alpha.1
pre
2 CVEs
CVE-2023-25656
GO-2023-1589
GHSA-87x9-7grx-m28v
Jul 11, 2023
Denial of service from memory exhaustion in github.com/notaryproject/notation-go Parsing PKIX distinguished names containing the string "=#" can cause excessive memory consumption. Fixed in
1.0.0-rc.3
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-33959
GO-2023-1832
GHSA-xhg5-42rf-296r
Jun 26, 2023
Verification bypass in github.com/notaryproject/notation-go An attacker who controls or compromises a registry can lead a user to verify the wrong artifact. Fixed in
1.0.0-rc.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.7.0-alpha.1
pre
Dependencies (2)
|