Fetching from the wire…
Security2026-08-29 · source-backed
GHSA-73p9-6hrp-8qhr is a self-reported set of fail-open bugs in a tool whose entire purpose is trustworthy verification. A require_signing policy gate could be satisfied by a forgeable or empty field, so an unsigned bundle receipt passed a "signing required" check. A CI verification path reported success regardless of the underlying result. A release-verification gate advertised policy limits it never enforced. Fixed in 1.7.0. Filed here as a worked example of the pattern where a supply-chain gate is declared and never actually checked. (GitHub Advisory)
Each link below shares sources, entities, or timing with this story.
Shared entities / Same source domain / Earlier coverage / Tension
Both cover GHSA, GitHub Advisory; reported by the same outlet (github.com); earlier GHSA coverage from 2026-08-27.
Both cover GHSA, GitHub Advisory; reported by the same outlet (github.com); earlier GHSA coverage from 2026-08-27.
Both cover Fixed, GHSA; reported by the same outlet (github.com); earlier Fixed coverage from 2026-08-26.
Shared entities / Same source domain / Earlier coverage
Both cover GHSA, GitHub Advisory; reported by the same outlet (github.com); earlier GHSA coverage from 2026-08-27.
Both cover GHSA, GitHub Advisory; reported by the same outlet (github.com); earlier GHSA coverage from 2026-08-27.
Both cover Fixed, GHSA; reported by the same outlet (github.com); earlier Fixed coverage from 2026-08-26.
Both cover Fixed, GHSA; reported by the same outlet (github.com); earlier Fixed coverage from 2026-08-26.
Both cover Fixed, GHSA; reported by the same outlet (github.com); earlier Fixed coverage from 2026-08-23.