nono-cli is vulnerable to Improper Verification of Cryptographic Signature
66
Medium Risk
Pack trust-bundle verification skips a Sigstore entry when installed_path does not resolve to a file, and still returns success. The earlier artifact-hash loop uses the lockfile path, so a mismatched bundle path skips signer checks while the SHA256 check on the real artifact still passes. The fix fails closed when a bundle entry points at a missing path.
You are affected if you are using a version that falls within the vulnerable range and you install packs that re-verify stored Sigstore trust bundles.
nono-cli is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.1 - 0.77.0.
Upgrade the nono-cli library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.