{"api_version":"v1","generated_at":"2026-10-09T09:40:00+00:00","product":{"cve_count":3,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-sigstore-sigstore-go-531dfaaed995","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"sigstore-go","next_cursor":null,"observations":[{"affected":"< 1.2.1","affected_versions_present":true,"cve_id":"CVE-2026-54787","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54787","fixed":"1.2.1.","last_modified":"2026-07-31T23:36:13.441Z","patch_url":"https://github.com/sigstore/sigstore-go/security/advisories/GHSA-wqqc-jjcq-vfxm","primary_source":"","published":"2026-07-31T21:58:14.156Z"},{"affected":"< 1.2.0","affected_versions_present":true,"cve_id":"CVE-2026-49834","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49834","fixed":"1.2.0.","last_modified":"2026-07-17T19:42:17.005Z","patch_url":"https://github.com/sigstore/sigstore-go/pull/633","primary_source":"","published":"2026-07-17T19:20:06.140Z"},{"affected":"< 0.6.1","affected_versions_present":true,"cve_id":"CVE-2024-45395","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-45395","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-05T14:25:27.922Z","patch_url":"https://github.com/sigstore/sigstore-go/commit/01e70e89e58226286d7977b4dba43b6be472b12c","primary_source":"","published":"2024-09-04T20:15:08.769Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"sigstore"}}
