github.com/theupdateframework/go-tuf
Activity
- Latest release
- 2y ago
- Total releases
- 20
- Cadence
- ~3 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Mar 11, 2022
| Version | Released | |
|---|---|---|
v0.7.0
minor
|
v0.7.0
minor
Dependencies (9)
+ 1 more |
|
v0.6.1
patch
|
v0.6.1
patch
Dependencies (9)
+ 1 more |
|
v0.6.0
minor
|
v0.6.0
minor
Dependencies (9)
+ 1 more |
|
v0.5.2
patch
|
v0.5.2
patch
Dependencies (9)
+ 1 more |
|
v0.5.1
patch
|
v0.5.1
patch
Dependencies (9)
+ 1 more |
|
v0.5.0
minor
|
v0.5.0
minor
Dependencies (9)
+ 1 more |
|
v0.4.0
minor
|
v0.4.0
minor
Dependencies (8)
|
|
v0.3.2
patch
|
v0.3.2
patch
Dependencies (8)
|
|
v0.3.1
patch
1 CVE
GO-2022-1004
GHSA-3633-5h82-39pq
Sep 21, 2022
Improper handling of keys in github.com/theupdateframework/go-tuf An attacker with the ability to insert public keys into a TUF repository can cause clients to accept a staged change that has not been signed by the correct threshold of signatures. Fixed in
0.3.2
References Updated May 20, 2024 · Source: OSV.dev |
v0.3.1
patch
Dependencies (8)
|
|
v0.3.0
minor
1 CVE
GO-2022-1004
GHSA-3633-5h82-39pq
Sep 21, 2022
Improper handling of keys in github.com/theupdateframework/go-tuf An attacker with the ability to insert public keys into a TUF repository can cause clients to accept a staged change that has not been signed by the correct threshold of signatures. Fixed in
0.3.2
References Updated May 20, 2024 · Source: OSV.dev |
v0.3.0
minor
Dependencies (8)
|
|
v0.2.0
minor
2 CVEs
GO-2022-1004
GHSA-3633-5h82-39pq
Sep 21, 2022
Improper handling of keys in github.com/theupdateframework/go-tuf An attacker with the ability to insert public keys into a TUF repository can cause clients to accept a staged change that has not been signed by the correct threshold of signatures. Fixed in
0.3.2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29173
GO-2022-0444
GHSA-66x3-6cw3-v5gj
Jul 01, 2022
Version rollback attack in github.com/theupdateframework/go-tuf The TUF client is vulnerable to rollback attacks, in which an attacker causes a client to install software older than the software the client previously knew to be available. Fixed in
0.3.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.2.0
minor
Dependencies (8)
|
|
v0.1.15
patch
2 CVEs
GO-2022-1004
GHSA-3633-5h82-39pq
Sep 21, 2022
Improper handling of keys in github.com/theupdateframework/go-tuf An attacker with the ability to insert public keys into a TUF repository can cause clients to accept a staged change that has not been signed by the correct threshold of signatures. Fixed in
0.3.2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29173
GO-2022-0444
GHSA-66x3-6cw3-v5gj
Jul 01, 2022
Version rollback attack in github.com/theupdateframework/go-tuf The TUF client is vulnerable to rollback attacks, in which an attacker causes a client to install software older than the software the client previously knew to be available. Fixed in
0.3.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.15
patch
Dependencies (8)
|
|
v0.1.14
patch
2 CVEs
GO-2022-1004
GHSA-3633-5h82-39pq
Sep 21, 2022
Improper handling of keys in github.com/theupdateframework/go-tuf An attacker with the ability to insert public keys into a TUF repository can cause clients to accept a staged change that has not been signed by the correct threshold of signatures. Fixed in
0.3.2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29173
GO-2022-0444
GHSA-66x3-6cw3-v5gj
Jul 01, 2022
Version rollback attack in github.com/theupdateframework/go-tuf The TUF client is vulnerable to rollback attacks, in which an attacker causes a client to install software older than the software the client previously knew to be available. Fixed in
0.3.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.14
patch
Dependencies (8)
|
|
v0.1.13
patch
2 CVEs
GO-2022-1004
GHSA-3633-5h82-39pq
Sep 21, 2022
Improper handling of keys in github.com/theupdateframework/go-tuf An attacker with the ability to insert public keys into a TUF repository can cause clients to accept a staged change that has not been signed by the correct threshold of signatures. Fixed in
0.3.2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29173
GO-2022-0444
GHSA-66x3-6cw3-v5gj
Jul 01, 2022
Version rollback attack in github.com/theupdateframework/go-tuf The TUF client is vulnerable to rollback attacks, in which an attacker causes a client to install software older than the software the client previously knew to be available. Fixed in
0.3.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.13
patch
Dependencies (8)
|
|
v0.1.12
patch
2 CVEs
GO-2022-1004
GHSA-3633-5h82-39pq
Sep 21, 2022
Improper handling of keys in github.com/theupdateframework/go-tuf An attacker with the ability to insert public keys into a TUF repository can cause clients to accept a staged change that has not been signed by the correct threshold of signatures. Fixed in
0.3.2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29173
GO-2022-0444
GHSA-66x3-6cw3-v5gj
Jul 01, 2022
Version rollback attack in github.com/theupdateframework/go-tuf The TUF client is vulnerable to rollback attacks, in which an attacker causes a client to install software older than the software the client previously knew to be available. Fixed in
0.3.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.12
patch
Dependencies (8)
|
|
v0.1.11
patch
2 CVEs
GO-2022-1004
GHSA-3633-5h82-39pq
Sep 21, 2022
Improper handling of keys in github.com/theupdateframework/go-tuf An attacker with the ability to insert public keys into a TUF repository can cause clients to accept a staged change that has not been signed by the correct threshold of signatures. Fixed in
0.3.2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29173
GO-2022-0444
GHSA-66x3-6cw3-v5gj
Jul 01, 2022
Version rollback attack in github.com/theupdateframework/go-tuf The TUF client is vulnerable to rollback attacks, in which an attacker causes a client to install software older than the software the client previously knew to be available. Fixed in
0.3.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.11
patch
Dependencies (8)
|
|
v0.1.10
patch
2 CVEs
GO-2022-1004
GHSA-3633-5h82-39pq
Sep 21, 2022
Improper handling of keys in github.com/theupdateframework/go-tuf An attacker with the ability to insert public keys into a TUF repository can cause clients to accept a staged change that has not been signed by the correct threshold of signatures. Fixed in
0.3.2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29173
GO-2022-0444
GHSA-66x3-6cw3-v5gj
Jul 01, 2022
Version rollback attack in github.com/theupdateframework/go-tuf The TUF client is vulnerable to rollback attacks, in which an attacker causes a client to install software older than the software the client previously knew to be available. Fixed in
0.3.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.10
patch
Dependencies (8)
|
|
v0.1.9
patch
2 CVEs
GO-2022-1004
GHSA-3633-5h82-39pq
Sep 21, 2022
Improper handling of keys in github.com/theupdateframework/go-tuf An attacker with the ability to insert public keys into a TUF repository can cause clients to accept a staged change that has not been signed by the correct threshold of signatures. Fixed in
0.3.2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29173
GO-2022-0444
GHSA-66x3-6cw3-v5gj
Jul 01, 2022
Version rollback attack in github.com/theupdateframework/go-tuf The TUF client is vulnerable to rollback attacks, in which an attacker causes a client to install software older than the software the client previously knew to be available. Fixed in
0.3.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.9
patch
Dependencies (8)
|
|
v0.1.8
patch
2 CVEs
GO-2022-1004
GHSA-3633-5h82-39pq
Sep 21, 2022
Improper handling of keys in github.com/theupdateframework/go-tuf An attacker with the ability to insert public keys into a TUF repository can cause clients to accept a staged change that has not been signed by the correct threshold of signatures. Fixed in
0.3.2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29173
GO-2022-0444
GHSA-66x3-6cw3-v5gj
Jul 01, 2022
Version rollback attack in github.com/theupdateframework/go-tuf The TUF client is vulnerable to rollback attacks, in which an attacker causes a client to install software older than the software the client previously knew to be available. Fixed in
0.3.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.8
patch
Dependencies (8)
|
|
v0.1.7
initial
2 CVEs
GO-2022-1004
GHSA-3633-5h82-39pq
Sep 21, 2022
Improper handling of keys in github.com/theupdateframework/go-tuf An attacker with the ability to insert public keys into a TUF repository can cause clients to accept a staged change that has not been signed by the correct threshold of signatures. Fixed in
0.3.2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-29173
GO-2022-0444
GHSA-66x3-6cw3-v5gj
Jul 01, 2022
Version rollback attack in github.com/theupdateframework/go-tuf The TUF client is vulnerable to rollback attacks, in which an attacker causes a client to install software older than the software the client previously knew to be available. Fixed in
0.3.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.7
initial
Dependencies (8)
|