mediumVulnerability

GHSA-h829-5cg7-6hff

gitverify is still a prototype. ### Impact The bug is related to `requireSignedTags` which is on by default: an unsigned annotated tag would pass the verification. The commit pointed to by the tag would still have to be signed by a maintainer or a contributor. ### Patches Since the initial commit, fixed in c2c60da05d5c73621d0ce7ea02770bacd79ec8b1 (no semantic versions yet). ### Workarounds No

Properties

ghsa_id
GHSA-h829-5cg7-6hff
severity
medium
summary
gitverify has improper tag signature verification
cve_id
GHSA-h829-5cg7-6hff
is_ghsa_only
true
ghsa_published
2026-04-24T20:42:22Z
source_url
https://github.com/advisories/GHSA-h829-5cg7-6hff
ghsa_updated
2026-04-24T20:42:25Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]go/github.com/supply-chain-tools/gitverify

AFFECTS (1)

[Software]go/github.com/supply-chain-tools/gitverify

HAS_WEAKNESS (1)

[Weakness]Improper Verification of Cryptographic Signature

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph