Junglewise Threat Intelligence

gitverify has improper tag signature verification

Severity: medium · Published 2026-04-24

Technologies: github.com/supply-chain-tools/gitverify (Go). Vendors: Go.

Executive brief

gitverify is still a prototype.

### Impact The bug is related to `requireSignedTags` which is on by default: an unsigned annotated tag would pass the verification. The commit pointed to by the tag would still have to be signed by a maintainer or a contributor.

### Patches Since the initial commit, fixed in c2c60da05d5c73621d0ce7ea02770bacd79ec8b1 (no semantic versions yet).

### Workarounds No

Affected products

  • Go github.com/supply-chain-tools/gitverify

References

Related threats