slsa-verifier vulnerable to mproper validation of npm's publish attestations in github.com/slsa-framework/slsa-verifier
{ "url": "https://pkg.go.dev/vuln/GO-2023-2188", "review_status": "UNREVIEWED" }