Disclosure Open Original ↗
Insufficient validation of integration timestamp in sigstore-python
Type
Disclosure
Client
sigstore-python
Date
2024
Domain
Supply Chain
Effort
—
Section
—
Related
- 2026-04 PyPI Warehouse Audit
- 2025 Attestations: a new generation of signatures on PyPI Talk
- 2024 The Next 5 Years of Supply Chain Security on PyPI Talk
- 2024 PEP 740 and PyPI: Bootstrapping Provenance for the Python Ecosystem Talk
- 2024 Imagining a zero-trust future for PyPI Talk
- 2024 Build Provenance: Lessons (so far) from Homebrew Talk