Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Validate digests of data downloaded while fetching sigstore attachments
This is not a security vulnerability because the registry can just as well send a manifest modified to match, but doing this correctly protects us in case this function were used for other purposes in the future. Fixes #2687. Signed-off-by: Miloslav Trmač <[email protected]>
- Loading branch information