Sigstore vulnerabilities

29 CVEs affecting Sigstore products, 0 known to be exploited (CISA KEV), with EPSS scores. Most affected: Cosign, Gitsign, Sigstore-Js, Sigstore-Go, Sigstore-Java.