Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Is there an audit report for v2? #304

Open
CharlieMc0 opened this issue Sep 4, 2024 · 3 comments
Open

Is there an audit report for v2? #304

CharlieMc0 opened this issue Sep 4, 2024 · 3 comments

Comments

@CharlieMc0
Copy link

Is there a public audit report for version 2.0.0? It seems like you fixed a number of audit findings but there is no public report verifying the fixes or that new bugs were not introduced.

@STdevK
Copy link

STdevK commented Sep 5, 2024

The 2019 audit report includes security findings and fixes implemented. Can you share with us what are some of your concerns about v2.0.0?

@CharlieMc0
Copy link
Author

I'd like to know if the 84 commits between v1.1.1 and v2.0.2 have been reviewed by an independent 3rd party and is the report is public?

I wasn't able to find any additional reports in this repo and I am hoping it's available but hasn't been uploaded. I am not a cryptograpy expert so I have to use 3rd party audits and whether the code has been battle tested in public to determine the security and safety of it. I am with one of the many projects who rely on a fork of TSS-lib and we're trying to determine the best path forward whether we rely on your recent upgrades or go our own direction.

I appreciate any help and insights into how the code has been verified and tested. Thanks

@CharlieMc0
Copy link
Author

Any information you can share here? And which version do you run internally?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants