GitHub attestation tool verified an unreleased container image, researchers find
Security researchers discovered that GitHub's 'gh attestation verify' command returned a passing result for a container image that had never been officially released. The issue stems from how the tool handles multi-platform OCI image indexes, where a signed attestation can cover a digest that does not correspond to the intended release manifest. Investigators traced the problem through multiple layers of container metadata, including image indexes, platform manifests, and Sigstore bundles attached via the OCI referrers API. The finding highlights a gap between cryptographic signature verification and confirming that a specific digest matches what a project actually shipped. The researchers note that checking provenance alone is insufficient without also validating the digest against an authoritative release manifest.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in