github.com/siderolabs/go-api-signature is vulnerable to Race Condition
70
High Risk
Affected versions of the package are vulnerable to a race condition in the signing method of their PGP (Pretty Good Privacy) key management when using multiple threads.
You are affected if you are using a version that falls within the vulnerable range.
github.com/siderolabs/go-api-signature is vulnerable to Race Condition in versions 0.1.0 - 0.3.4.
Upgrade the github.com/siderolabs/go-api-signature library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant