Fedora Account System
Red Hat Associate
Red Hat Customer
The documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked. Applications that rely on certificateOIDs to restrict which certificates may sign artifacts receive no protection. Unauthorized certificates that should be rejected on extension policy are accepted. Fixed in sigstore 4.1.1.