An open API service providing package, version and dependency metadata of many open source software ecosystems and registries.

Top 1.1% on proxy.golang.org
Top 0.2% dependent packages on proxy.golang.org
Top 0.3% dependent repos on proxy.golang.org
Top 2.4% forks on proxy.golang.org
Top 0.2% docker downloads on proxy.golang.org

proxy.golang.org : github.com/sigstore/rekor

Software Supply Chain Transparency Log

Registry - Source - Documentation - JSON
purl: pkg:golang/github.com/sigstore/rekor
Keywords: provenance , security , supply-chain , transparency-log
License: Apache-2.0
Latest release: 19 days ago
First release: over 4 years ago
Namespace: github.com/sigstore
Dependent packages: 496
Dependent repositories: 789
Stars: 681 on GitHub
Forks: 125 on GitHub
Docker dependents: 412
Docker downloads: 458,868,950
See more repository details: repos.ecosyste.ms
Last synced: about 2 hours ago

Moderate
GSA_kwCzR0hTQS1mcnF4LWpmY20tNmpqcs4AAzfX
malformed proposed intoto entries can cause a panic
Ecosystems: go
Packages: github.com/sigstore/rekor
Source: github
Published: almost 2 years ago
High
GSA_kwCzR0hTQS0yaDVoLTU5ZjUtYzV4Oc4AAzEu
Rekor's compressed archives can result in OOM conditions
Ecosystems: go
Packages: github.com/sigstore/rekor
Source: github
Published: almost 2 years ago