Skip to content

The use of the package browserify-sign could violate Microsoft crypto policy #4840

Open
@Majd-Zayyad-MSFT

Description

@Majd-Zayyad-MSFT

The library crypto-browserify which is a dependency in the newest version of botframework-connector uses browserify-sign which uses another package elliptic which, in turn uses hash.js. The use of the package hash.js violates Microsoft policy for the use approved crypto libraries.

We have received a security alert for having this module in our package-lock, and after investigating, it turns out that we get it from botframework-connector. We kindly ask that this module is either removed or that an investigation is opened to verify that no code flows into any of the functionality of hash.js.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions