github.com/sigstore/cosign/v3
Code signing and transparency for containers and binaries
Activity
- Latest release
- Jul 17, 2026
- Total releases
- 10
- Cadence
- ~38 days
- Last 12 months
- 10
Reach
- Stars
- 6.2k
Details
- First release
- Oct 07, 2025
| Version | Released | |
|---|---|---|
v3.1.2
patch
|
v3.1.2
patch
Dependencies (60)
+ 52 more |
|
v3.1.1
patch
|
v3.1.1
patch
Dependencies (61)
+ 53 more |
|
v3.1.0
minor
|
v3.1.0
minor
Dependencies (61)
+ 53 more |
|
v3.0.6
patch
|
v3.0.6
patch
Dependencies (61)
+ 53 more |
|
v3.0.5
patch
1 CVE
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
3.0.6
References Updated Jun 27, 2026 · Source: OSV.dev |
v3.0.5
patch
Dependencies (61)
+ 53 more |
|
v3.0.4
patch
2 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
3.0.6
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Fixed in
3.0.5
References Updated Jun 16, 2026 · Source: OSV.dev |
v3.0.4
patch
Dependencies (61)
+ 53 more |
|
v3.0.3
patch
3 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
3.0.6
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Fixed in
3.0.5
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
3.0.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.3
patch
Dependencies (61)
+ 53 more |
|
v3.0.2
patch
3 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
3.0.6
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Fixed in
3.0.5
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
3.0.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.2
patch
Dependencies (61)
+ 53 more |
|
v3.0.1
patch
3 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
3.0.6
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Fixed in
3.0.5
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
3.0.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.1
patch
Dependencies (61)
+ 53 more |
|
v3.0.0
initial
3 CVEs
CVE-2026-39395
GO-2026-5694
BIT-cosign-2026-39395
GHSA-w6c6-c85g-mmv6
Jun 25, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Cosign's verify-blob-attestation reports false positive when payload parsing fails in github.com/sigstore/cosign Fixed in
3.0.6
References Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-24122
GO-2026-4529
BIT-cosign-2026-24122
GHSA-wfqv-66vq-46rm
Feb 23, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped in github.com/sigstore/cosign Fixed in
3.0.5
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-22703
GO-2026-4309
BIT-cosign-2026-22703
GHSA-whqx-f9j3-ch6m
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign Fixed in
3.0.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.0.0
initial
Dependencies (61)
+ 53 more |