Vulnerabilities/

sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced

Severity:
High

Description

The documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked.

Recommendation

Update the sigstore package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
sigstore
Anything's wrong? Let us know Last updated on July 01, 2026