jfrog / jfrog/jfrog-cli

Does github.com/sigstore/timestamp-authority CVE-2025-66564 affect jfrog-cli?

Open
#3,274 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

question
Dominant language
Go
Stars
595
Forks
307
Avg merge
4d 17h
Merged PRs (30d)
17

Description

CVE-2025-66564 was reported against github.com/sigstore/timestamp-authority , which is an indirect dependency of jfrog-cli. Fix is included in timestamp-authority v2.0.3 and newer, while jfrog-cli included v1.2.9. Is jfrog-cli affected?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with go.mod around line 216 and compare the included timestamp-authority v1.2.9 dependency with CVE-2025-66564 and the fixed v2.0.3 release. Trace how jfrog-cli uses the dependency, then document whether the CLI is affected and what version or remediation is required.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
cli, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.