{"id":"GHSA-h829-5cg7-6hff","aliases":["GO-2026-5416"],"url":"https://o3.security/vulnerability/GHSA-h829-5cg7-6hff","summary":"gitverify has improper tag signature verification","details":"gitverify is still a prototype.\n\n### Impact\nThe bug is related to `requireSignedTags` which is on by default: an unsigned annotated tag would pass the verification. The commit pointed to by the tag would still have to be signed by a maintainer or a contributor.\n\n### Patches\nSince the initial commit, fixed in c2c60da05d5c73621d0ce7ea02770bacd79ec8b1 (no semantic versions yet).\n\n### Workarounds\nNo","published":"2026-04-24T20:42:22Z","modified":"2026-06-25T23:11:49.182862451Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/supply-chain-tools/gitverify","fixedVersion":"0.0.0-20260421124901-c2c60da05d5c"}],"fix":{"url":"https://github.com/supply-chain-tools/gitverify/commit/c2c60da05d5c73621d0ce7ea02770bacd79ec8b1","label":"supply-chain-tools/gitverify@c2c60da"},"references":[{"type":"WEB","url":"https://github.com/supply-chain-tools/gitverify/security/advisories/GHSA-h829-5cg7-6hff"},{"type":"WEB","url":"https://github.com/supply-chain-tools/gitverify/commit/c2c60da05d5c73621d0ce7ea02770bacd79ec8b1"},{"type":"PACKAGE","url":"https://github.com/supply-chain-tools/gitverify"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-06-25T23:11:49.182862451Z"}}