{"api_version":"v1","generated_at":"2026-10-08T19:55:00+00:00","product":{"cve_count":4,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-sigstore-gitsign-99504d182c29","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"gitsign","next_cursor":null,"observations":[{"affected":"< 0.16.0","affected_versions_present":true,"cve_id":"CVE-2026-44309","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44309","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-15T17:43:59.446Z","patch_url":"","primary_source":"","published":"2026-05-15T16:22:51.260Z"},{"affected":">= 0.4.0, < 0.15.0","affected_versions_present":true,"cve_id":"CVE-2026-44310","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44310","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-15T16:44:36.684Z","patch_url":"","primary_source":"","published":"2026-05-15T16:17:53.558Z"},{"affected":"< 0.11.0","affected_versions_present":true,"cve_id":"CVE-2024-51746","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-51746","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-11-05T20:30:02.393Z","patch_url":"","primary_source":"","published":"2024-11-05T18:54:39.494Z"},{"affected":">= 0.6.0, < 0.8.0","affected_versions_present":true,"cve_id":"CVE-2023-47122","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-47122","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-03T15:24:07.931Z","patch_url":"https://github.com/sigstore/gitsign/security/advisories/GHSA-xvrc-2wvh-49vc","primary_source":"","published":"2023-11-10T21:33:55.421Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"sigstore"}}
