Affected by GO-2024-2582
and 4 other vulnerabilities
GO-2024-2582: Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder
GO-2024-2864: Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder
GO-2024-2871: Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder
GO-2024-2885: Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder
GO-2024-2934: Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder
package
Version:
v0.0.25
Opens a new window with list of versions in this module.
Published: Jan 16, 2024
License: Apache-2.0
Opens a new window with license information.
Imports: 22
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation
¶
Package container provides the tools to verify a container artifact using sigstore
func BuildImageRef(registry, owner, artifact, version string) string
BuildImageRef returns the OCI image reference
Verify verifies a container artifact using sigstore
Source Files
¶
Click to show internal directories.
Click to hide internal directories.