Skip to content

feat: Add Sigstore v2/v3 compatibility verification workflow

722f2af
Select commit
Loading
Failed to load commit list.
Draft

feat: Add Sigstore v2/v3 compatibility verification workflow #1725

feat: Add Sigstore v2/v3 compatibility verification workflow
722f2af
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Dec 5, 2025 in 4s

2 new alerts including 2 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 2 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 122 in .github/workflows/sigstore-verify-compatibility.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check warning on line 154 in .github/workflows/sigstore-verify-compatibility.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {}