PolicyController before 0.2.1 may bypass attestation verification in github.com/sigstore/policy-controller
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-0759" }