Base library for Sigstore
89%
Total Score
91
100
72
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-48758 @sigstore/core is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.0 - 3.2.0. | 0.0.0 - 3.2.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant