Cosign · Vulnerability Disclosure

Cosign Vulnerability Disclosure

Vulnerability disclosure

Sigstore publishes a full written security vulnerability process covering every project in the sigstore GitHub organization, Cosign included. It names a standing Security Response Committee, a reporting address, an acknowledgement SLA and the disclosure/patch/announce timeline.

Cosign runs a coordinated vulnerability disclosure program on Hackerone.

Apache 2.0AttestationsCLICode SigningContainersFulcioGoKeylessOCIOIDCOpen-SourceRekorSigstoreSupply ChainTransparency LogVerification
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
specification: API Commons VulnerabilityDisclosure
specificationVersion: '0.1'
provider: Cosign
providerId: cosign
generated: '2026-09-07'
method: searched
source: https://github.com/sigstore/.github/blob/main/SECURITY.md
description: >-
  Sigstore publishes a full written security vulnerability process covering every project in the
  sigstore GitHub organization, Cosign included. It names a standing Security Response Committee, a
  reporting address, an acknowledgement SLA and the disclosure/patch/announce timeline.
program:
  published: true
  policy_url: https://github.com/sigstore/.github/blob/main/SECURITY.md
  repo_policy_url: https://github.com/sigstore/cosign/security/policy
  advisories_url: https://github.com/sigstore/cosign/security/advisories
  contact_email: security@sigstore.dev
  pgp: >-
    Available on request — reporters uncomfortable sending in the clear are asked to email requesting
    a public PGP key to use for encryption.
  acknowledgement_sla: 24 hours
  model: Responsible / coordinated disclosure
  bug_bounty: false
  bounty_note: >-
    No bug bounty program (HackerOne / Bugcrowd / Intigriti) was found for Sigstore or Cosign as of
    2026-09-07. Disclosure is unpaid and coordinated through the Security Response Committee.
  safe_harbor_stated: false
governance:
  body: Security Response Committee (SRC)
  size_target: 3-5 members
  vendor_diversity_rule: No more than a 2:1 ratio of representation from any single vendor
  responsibilities:
    - Triage — assess impact and whether the code is in Sigstore or upstream
    - Infra — create a security advisory and temporary private fork for the fix team
    - Disclosure — public messaging, affected versions, advisory notice
    - Release — cut the release carrying the fix and notify the public
process:
  fix_team_formed_within: 24 hours of disclosure
  fix_development_window: 1-7 days of disclosure
  fix_release_window: 1-21 days of disclosure
  cve_requested: true
  severity_scoring: CVSS (with SRC discretion)
  recommended_release_time: 16:00 UTC on a non-Friday weekday
  announcement_channels:
    - sigstore-dev@googlegroups.com
    - https://sigstore.slack.com (general and development channels)
  retrospective: Blameless retrospective sent to sigstore-dev@googlegroups.com 1-3 days after release
  embargo_rule: >-
    Severity and handling are discussed only inside the security advisory, never in public repos or
    Slack channels.
evidence:
  - url: https://github.com/sigstore/.github/blob/main/SECURITY.md
    status: 200
    checked: '2026-09-07'
  - url: https://github.com/sigstore/cosign/security
    status: 200
    checked: '2026-09-07'
  - url: https://sigstore.dev/.well-known/security.txt
    status: 200
    checked: '2026-09-07'
    note: >-
      NOT a security.txt. sigstore.dev is a single-page app whose catch-all answers 200 with the same
      4,248-byte HTML shell for every /.well-known/* path. No RFC 9116 file is served on any Sigstore
      host — see well-known/cosign-well-known.yml.
recent_advisories:
  - id: GHSA-whqx-f9j3-ch6m
    fixed_in:
      - v3.0.4
      - v2.6.2
    date: '2026-01-09'
    note: Bundle verify path for old bundle/trusted root.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/cosign-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.