SAP Knowledge Base Article - Preview

3781989 - Sigstore npm triggers security scanner vulnerability check

Symptom

  • The sigstore npm package <=4.1.0 contains a vulnerability (GHSA-4hvv-6rrq-783j) where certificateOIDs passed to sigstore.verify() are silently dropped, bypassing OID-based certificate constraints.
  • The vulnerability is introduced via the transitive dependency chain: @ui5/cli@4.0.57 → @ui5/project@4.0.17 → pacote@19.0.2 → sigstore@3.1.0.
  • Security tools (for example, npm audit) flag sigstore <=4.1.0 in the project due to this dependency chain.


Read more...

Environment

SAPUI5 

Product

UI5 automation framework all versions

Keywords

sigstore, ghsa-4hvv-6rrq-783j, @sigstore/core, dsse, pacote 19, pacote 20, @ui5/project, @ui5/cli, npm audit, verifySignatures, verifyAttestations, transitive dependency, dependency chain, security scanner, vulnerability flagged , KBA , CA-UI5-COR-FND , Foundation team , CA-UI5-COR , Core and Runtime , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.