Skip to content

v2.2.2 - EventChain round-1 crypto audit fixes

Choose a tag to compare

@sadhaka sadhaka released this 21 May 15:00
· 145 commits to main since this release

Round-1 audit hardening. Length-prefixed and domain-tagged canonical message for an injective encoding (no field-boundary forgery). Strict canonicalization fails closed on non-JSON values instead of collapsing to null. Lone-surrogate rejection on every signed string. Verify-before-mutate snapshot load. Constant-time signature compare.