sigstore
A pure-ruby implementation of sigstore signature verification
Activity
- Latest release
- 6mo ago
- Total releases
- 5
- Cadence
- ~3 months
- Last 12 months
- 2
Reach
- Stars
- —
Details
- License
- Apache-2.0
- First release
- Oct 21, 2024
| Version | Released | |
|---|---|---|
0.2.3
patch
| ||
0.2.2
patch
1 CVE
CVE-2026-31830
GHSA-mhg6-2q2v-9h2c
Mar 11, 2026
sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digest
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary
DetailsIn
When The message_signature code path is not affected. ImpactAn attacker who possesses a valid signed DSSE bundle containing an in-toto attestation for artifact A can present it as a valid attestation for a different artifact B. All other verification checks (DSSE envelope signature, certificate chain, Rekor inclusion, SCTs, policy) pass because they are independent of the artifact content. Only the in-toto subject digest check detects the mismatch, and its result is discarded. This allows an attacker to bypass artifact-to-attestation binding for any consumer that relies on WorkaroundsNone. Consumers cannot work around this without patching the library. Affected versions
0.1.1
0.2.0
0.2.1
0.2.2
Fixed in
0.2.3
References Updated Mar 19, 2026 · Source: OSV.dev | ||
0.2.1
patch
1 CVE
CVE-2026-31830
GHSA-mhg6-2q2v-9h2c
Mar 11, 2026
sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digest
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary
DetailsIn
When The message_signature code path is not affected. ImpactAn attacker who possesses a valid signed DSSE bundle containing an in-toto attestation for artifact A can present it as a valid attestation for a different artifact B. All other verification checks (DSSE envelope signature, certificate chain, Rekor inclusion, SCTs, policy) pass because they are independent of the artifact content. Only the in-toto subject digest check detects the mismatch, and its result is discarded. This allows an attacker to bypass artifact-to-attestation binding for any consumer that relies on WorkaroundsNone. Consumers cannot work around this without patching the library. Affected versions
0.1.1
0.2.0
0.2.1
0.2.2
Fixed in
0.2.3
References Updated Mar 19, 2026 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2026-31830
GHSA-mhg6-2q2v-9h2c
Mar 11, 2026
sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digest
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary
DetailsIn
When The message_signature code path is not affected. ImpactAn attacker who possesses a valid signed DSSE bundle containing an in-toto attestation for artifact A can present it as a valid attestation for a different artifact B. All other verification checks (DSSE envelope signature, certificate chain, Rekor inclusion, SCTs, policy) pass because they are independent of the artifact content. Only the in-toto subject digest check detects the mismatch, and its result is discarded. This allows an attacker to bypass artifact-to-attestation binding for any consumer that relies on WorkaroundsNone. Consumers cannot work around this without patching the library. Affected versions
0.1.1
0.2.0
0.2.1
0.2.2
Fixed in
0.2.3
References Updated Mar 19, 2026 · Source: OSV.dev | ||
0.1.1
initial
1 CVE
CVE-2026-31830
GHSA-mhg6-2q2v-9h2c
Mar 11, 2026
sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digest
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary
DetailsIn
When The message_signature code path is not affected. ImpactAn attacker who possesses a valid signed DSSE bundle containing an in-toto attestation for artifact A can present it as a valid attestation for a different artifact B. All other verification checks (DSSE envelope signature, certificate chain, Rekor inclusion, SCTs, policy) pass because they are independent of the artifact content. Only the in-toto subject digest check detects the mismatch, and its result is discarded. This allows an attacker to bypass artifact-to-attestation binding for any consumer that relies on WorkaroundsNone. Consumers cannot work around this without patching the library. Affected versions
0.1.1
0.2.0
0.2.1
0.2.2
Fixed in
0.2.3
References Updated Mar 19, 2026 · Source: OSV.dev |