Skip to content

Security review welcome #1

Description

@major-matters

We actively want researcher eyes on this v0. If you find a fail-open, a signature bypass, an SSRF path, or any way to defeat a guarantee listed in SECURITY.md, please comment here or open a new issue. Credit given.

This is a v0 release: independently hardened (CodeQL, bandit, semgrep, property-based tests, adversarial tier 1-2 reviews, all green in CI) but not third-party audited. See SECURITY.md.

The shared crypto core (Ed25519 + RFC 8785 canonicalization) and the did:web SSRF guard are the highest-value targets.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions