Skip to content

Conversation

@dnegreira
Copy link
Member

Update advisories for CVE-2025-66564 and CVE-2025-66506

github.com/sigstore/fulcio and github.com/sigstore/timestamp-authority
are transitive dependencies pulled in by github.com/sigstore/cosign.

We have tried to bump the transitive dependencies in falcoctl
without success, we need to wait for the migration to sigstore v3 to
happen in falcoctl in order to fix these CVEs.

The bump has already happened in the upstream sigstore v3.0.3 version. [1]

[1] sigstore/cosign@5a60384

Signed-off-by: David Negreira david.negreira@chainguard.dev

Update advisories for CVE-2025-66564 and CVE-2025-66506

github.com/sigstore/fulcio and github.com/sigstore/timestamp-authority
are transitive dependencies pulled in by github.com/sigstore/cosign.

We have tried to bump the transitive dependencies in falcoctl
without success, we need to wait for the migration to sigstore v3 to
happen in falcoctl in order to fix these CVEs.

The bump has already happened in the upstream sigstore v3.0.3 version. [1]

[1] sigstore/cosign@5a60384

Signed-off-by: David Negreira <david.negreira@chainguard.dev>
Copy link
Member

@aborrero aborrero left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@aborrero aborrero added this pull request to the merge queue Dec 12, 2025
Merged via the queue into wolfi-dev:main with commit d26f68c Dec 12, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants