Skip to content
This repository has been archived by the owner on Mar 10, 2024. It is now read-only.

chainguard-dev/is-sigstore-psychic

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Sigstore Pyschic Signature Checker

Sigstore is not vulnerable to the psychic signature vulnerability in Java.

This repository demonstrates this in two ways:

  1. cmd/uploadbadsig attempts to upload a "psychic signature" to Rekor and fails.

  2. cmd/csvcheck takes in a CSV file containing signatures from Rekor, and scans for "psychic signatures." signatures.csv contains an example, including a fake psychic signature.

About

Checking sigstore susceptibility to psychic signatures

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published