Executive brief
gitverify is still a prototype.
### Impact The bug is related to `requireSignedTags` which is on by default: an unsigned annotated tag would pass the verification. The commit pointed to by the tag would still have to be signed by a maintainer or a contributor.
### Patches Since the initial commit, fixed in c2c60da05d5c73621d0ce7ea02770bacd79ec8b1 (no semantic versions yet).
### Workarounds No
Affected products
- Go github.com/supply-chain-tools/gitverify