PolicyController before 0.2.1 may bypass attestation verification in github.com/sigstore/policy-controller
{ "url": "https://pkg.go.dev/vuln/GO-2022-0759", "review_status": "UNREVIEWED" }