A malicious proxy/registry can bypass verifyImages rules.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-1180" }
{ "imports": [ { "path": "github.com/kyverno/kyverno/pkg/engine", "symbols": [ "imageVerifier.verifyAttestation", "imageVerifier.verifyAttestations", "imageVerifier.verifyAttestorSet", "imageVerifier.verifyAttestors", "imageVerifier.verifyImage" ] } ] }