gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers in github.com/sigstore/gitsign
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2026-5212" }
"https://vuln.go.dev/ID/GO-2026-5212.json"