Vulnerabilities/

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

Severity:
High

Description

This is a credential-exposure / credential-confusion issue.

Recommendation

Update the @sigstore/oci package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@sigstore/oci
Anything's wrong? Let us know Last updated on July 21, 2026