sigstore-website icon indicating copy to clipboard operation
sigstore-website copied to clipboard

Codebase for sigstore.dev

Results 20 sigstore-website issues
Sort by recently updated
recently updated
newest added

Bumps [express](https://github.com/expressjs/express) from 4.18.2 to 4.19.2. Release notes Sourced from express's releases. 4.19.2 What's Changed Improved fix for open redirect allow list bypass Full Changelog: https://github.com/expressjs/express/compare/4.19.1...4.19.2 4.19.1 What's Changed Fix...

dependencies

Bumps [webpack-dev-middleware](https://github.com/webpack/webpack-dev-middleware) from 5.3.3 to 5.3.4. Release notes Sourced from webpack-dev-middleware's releases. v5.3.4 5.3.4 (2024-03-20) Bug Fixes security: do not allow to read files above (#1779) (189c4ac) Changelog Sourced from...

dependencies

Bumps [follow-redirects](https://github.com/follow-redirects/follow-redirects) from 1.15.2 to 1.15.6. Commits 35a517c Release version 1.15.6 of the npm package. c4f847f Drop Proxy-Authorization across hosts. 8526b4a Use GitHub for disclosure. b1677ce Release version 1.15.5 of...

dependencies

Bumps [ip](https://github.com/indutny/node-ip) from 1.1.8 to 1.1.9. Commits 1ecbf2f 1.1.9 6a3ada9 lib: fixed CVE-2023-42282 and added unit test See full diff in compare view [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ip&package-manager=npm_and_yarn&previous-version=1.1.8&new-version=1.1.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any...

dependencies

Currently, due to the direct use of the readme for link previews, sending someone [https://www.sigstore.dev/](https://www.sigstore.dev/) results in a malformed preview description. For example, when sending someone the URL on Discord,...

enhancement

Signed-off-by: nikhilkalburgi #### Summary Add arrow between developers and publish signed artifact in svg #### Release Note NONE #### Documentation This PR Fixes img Resolves #300

**Description** There is No Arrow in [How sigstore works?](https://www.sigstore.dev/how-it-works) Sigstore Ecosystem Diagram between developers and publish signed artifact. ![image](https://github.com/sigstore/sigstore-website/assets/70331875/b7bf5aa3-f117-4d50-ae06-3172b5046d13) **I am willing take this task on me**

bug

**Description** The Card image in [How sigstore works?](https://www.sigstore.dev/how-it-works) needs to be centered for a better look ![image](https://github.com/sigstore/sigstore-website/assets/70331875/34b5316d-7e19-4cef-a2ae-d2cbc04365bf) Just compare the difference between Sign Card with center and Verify Card with...

enhancement

Bumps [postcss](https://github.com/postcss/postcss) from 8.4.25 to 8.4.31. Release notes Sourced from postcss's releases. 8.4.31 Fixed \r parsing to fix CVE-2023-44270. 8.4.30 Improved source map performance (by @​romainmenke). 8.4.29 Fixed Node#source.offset (by...

dependencies

Bumps [browserify-sign](https://github.com/crypto-browserify/browserify-sign) from 4.2.1 to 4.2.2. Changelog Sourced from browserify-sign's changelog. v4.2.2 - 2023-10-25 Fixed [Tests] log when openssl doesn't support cipher [#37](https://github.com/crypto-browserify/browserify-sign/issues/37) Commits Only apps should have lockfiles 09a8995...

dependencies