Gitsign's Rekor public keys fetched from upstream API instead of local TUF client. in github.com/sigstore/gitsign
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2023-2332" }