Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

What is your plan for next release? #242

Open
zargarzadehm opened this issue May 14, 2023 · 1 comment
Open

What is your plan for next release? #242

zargarzadehm opened this issue May 14, 2023 · 1 comment

Comments

@zargarzadehm
Copy link
Contributor

According to this article and these CVEs - CVE-2022–47930, CVE-2022–47931, CVE-2023–26556, and CVE-2023–26557 - some vulnerabilities have been found in the protocol and in this package. I found PR #233 related to 'Collision of Hash Values', but a new release has not been made yet. Can you tell me what your plan is for the next release, including this PR? Also, are there any side effects for other vulnerabilities in this library? If yes, do you have any plans to fix them and release a new version?

@DecoratedWings
Copy link

I have the same question as I stumbled upon the medium article in my analysis. Can a core maintainer kindly address this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants