Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Updated Maturity Disclaimer section #280

Merged
merged 3 commits into from Mar 18, 2022
Merged

Updated Maturity Disclaimer section #280

merged 3 commits into from Mar 18, 2022

Conversation

obstropolos
Copy link
Contributor

  • Updates the README to reflect security audit conducted by Trail of Bits

@obstropolos obstropolos requested a review from wyc March 18, 2022 19:19
@obstropolos obstropolos merged commit 3054819 into main Mar 18, 2022
@obstropolos obstropolos deleted the docs/audit-update branch March 18, 2022 20:48
@clehner
Copy link
Contributor

clehner commented Mar 24, 2022

DIDKit pull-requests related to this security assessment

The following are the fixes and partial fixes mentioned in the Fix Log (pages 86-93) of the referenced PDF.

Finding number Finding title Page number Pull requests
11 DIDKit CLI option to change tzkt_url is not documented 35 (partial) spruceid/ssi#357
15 DIDKit HTTP server is vulnerable to slowloris attacks 40 #233
16 DIDKit HTTP server is vulnerable to memory resource exhaustion 41 #229

See also the fixes in ssi: spruceid/ssi#408 (comment)

mountainmax-li pushed a commit to ott-creative/didkit that referenced this pull request Sep 14, 2022
* Updated Maturity Disclaimer section
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants