Advisories for Golang/Github.com/In-Toto/In-Toto-Golang package

2026

in-toto-golang and in-toto-python have inconsistent negation behavior

What kind of vulnerability is it? Who is impacted? in-toto-golang and in-toto-python both support glob patterns in artifact rules to indicate the artifacts that a rule applies to. Both support negations in character classes to indicate what should not be matched, but they used different operators to indicate the negation. in-toto-python uses ! while in-toto-golang used ^. A layout authored with the expectations of one implementation can therefore exhibit different …

2021