An open API service providing package, version and dependency metadata of many open source software ecosystems and registries.

Top 3.3% on proxy.golang.org
Top 0.9% dependent packages on proxy.golang.org
Top 1.1% dependent repos on proxy.golang.org
Top 4.2% forks on proxy.golang.org
Top 2.2% docker downloads on proxy.golang.org

proxy.golang.org : github.com/notaryproject/notation-go

Package notation provides signer and verifier for notation Sign and Verification. ExampleLocalSign demonstrates how to use signer.Sign to sign an artifact at local (without using a registry.Repository). ExampleLocalVerify demonstrates how to use verifier.Verify to verify a signature of the target artifact at local (without using a registry.Repository). ExampleRemoteSign demonstrates how to use notation.Sign to sign an artifact in the remote registry and push the signature to the remote. ExampleRemoteVerify demonstrates how to use notation.Verify to verify signatures of an artifact in the remote registry. Example_signWithTimestamp demonstrates how to use notation.Sign to sign an artifact with a RFC 3161 compliant timestamp countersignature and user trusted TSA root certificate Example_verifyWithTimestamp demonstrates how to use notation.Verify to verify signature of an artifact including RFC 3161 compliant timestamp countersignature

Registry - Source - Documentation - JSON
purl: pkg:golang/github.com/notaryproject/notation-go
License: Apache-2.0
Latest release: 2 months ago
First release: over 3 years ago
Namespace: github.com/notaryproject
Dependent packages: 29
Dependent repositories: 26
Stars: 36 on GitHub
Forks: 42 on GitHub
Docker dependents: 9
Docker downloads: 263,358
Total Commits: 206
Committers: 32
Average commits per author: 6.438
Development Distribution Score (DDS): 0.752
More commit stats: commits.ecosyste.ms
See more repository details: repos.ecosyste.ms
Last synced: 4 days ago

High
GSA_kwCzR0hTQS04N3g5LTdncngtbTI4ds4AAxw4
notation-go has excessive memory allocation on verification
Ecosystems: go
Packages: github.com/notaryproject/notation-go
Source: github
Published: over 2 years ago
Low
GSA_kwCzR0hTQS1xamgzLTRqM2gtdm13cM4ABDOr
notation-go has an OS error when setting CRL cache leads to denial of signature verification
Ecosystems: go
Packages: github.com/notaryproject/notation-go
Source: github
Published: 5 months ago
Moderate
GSA_kwCzR0hTQS00NXYzLTM4cGMtODc0ds4ABDOs
notation-go's timestamp signature generation lacks certificate revocation check
Ecosystems: go
Packages: github.com/notaryproject/notation-go
Source: github
Published: 5 months ago
High
GSA_kwCzR0hTQS14aGc1LTQycmYtMjk2cs4AAzr4
notation-go's verification bypass can cause users to verify the wrong artifact
Ecosystems: go
Packages: github.com/notaryproject/notation-go
Source: github
Published: about 2 years ago