Debian Package Tracker
Register | Log in
Subscribe

golang-github-sigstore-fulcio

Sigstore OIDC PKI (library)

Choose email to subscribe with

general
  • source: golang-github-sigstore-fulcio (main)
  • version: 1.7.1-1
  • maintainer: Debian Go Packaging Team (DMD)
  • uploaders: Reinhard Tartler [DMD]
  • arch: all
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 1.6.5-1
  • testing: 1.7.1-1
  • unstable: 1.7.1-1
versioned links
  • 1.6.5-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.7.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • golang-github-sigstore-fulcio-dev
action needed
A new upstream version is available: 1.8.3 high
A new upstream version 1.8.3 is available, you should consider packaging it.
Created: 2025-11-27 Last update: 2025-12-10 22:31
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2025-66506: Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.3, function identity.extractIssuerURL splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request with an (invalid) OIDC identity token in the payload containing many period characters, a call to extractIssuerURL incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. This vulnerability is fixed in 1.8.3.
Created: 2025-12-06 Last update: 2025-12-07 19:00
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2025-66506: Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.3, function identity.extractIssuerURL splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request with an (invalid) OIDC identity token in the payload containing many period characters, a call to extractIssuerURL incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. This vulnerability is fixed in 1.8.3.
Created: 2025-12-06 Last update: 2025-12-07 19:00
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2025-66506: (needs triaging) Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.3, function identity.extractIssuerURL splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request with an (invalid) OIDC identity token in the payload containing many period characters, a call to extractIssuerURL incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. This vulnerability is fixed in 1.8.3.

You can find information about how to handle this issue in the security team's documentation.

Created: 2025-12-06 Last update: 2025-12-07 19:00
news
[rss feed]
  • [2025-10-10] golang-github-sigstore-fulcio 1.7.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-07] Accepted golang-github-sigstore-fulcio 1.7.1-1 (source) into unstable (Simon Josefsson)
  • [2024-11-12] golang-github-sigstore-fulcio 1.6.5-1 MIGRATED to testing (Debian testing watch)
  • [2024-11-09] Accepted golang-github-sigstore-fulcio 1.6.5-1 (source) into unstable (Reinhard Tartler)
  • [2024-06-25] golang-github-sigstore-fulcio 1.2.0-2 MIGRATED to testing (Debian testing watch)
  • [2024-06-22] Accepted golang-github-sigstore-fulcio 1.2.0-2 (source) into unstable (Reinhard Tartler)
  • [2024-06-21] Accepted golang-github-sigstore-fulcio 1.2.0-1 (all source) into unstable (Debian FTP Masters) (signed by: Reinhard Tartler)
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.7.1-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing