—PyPI
PYSEC-2026-1923· CVE-2024-55655, GHSA-hhfg-fwrw-87w7sigstore has insufficient validation of integration timestamp during verification
Modified: 7/7/2026
package
pkg:pypi/sigstore
sigstore has insufficient validation of integration timestamp during verification
Modified: 7/7/2026
sigstore CSRF possibility in OIDC authentication during signing
Modified: 7/7/2026
sigstore has insufficient validation of integration timestamp during verification
Modified: 9/10/2026
sigstore CSRF possibility in OIDC authentication during signing
Modified: 7/7/2026