We actively want researcher eyes on this v0. If you find a fail-open, a signature bypass, an SSRF path, or any way to defeat a guarantee listed in SECURITY.md, please comment here or open a new issue. Credit given.
This is a v0 release: independently hardened (CodeQL, bandit, semgrep, property-based tests, adversarial tier 1-2 reviews, all green in CI) but not third-party audited. See SECURITY.md.
The shared crypto core (Ed25519 + RFC 8785 canonicalization) and the did:web SSRF guard are the highest-value targets.
We actively want researcher eyes on this v0. If you find a fail-open, a signature bypass, an SSRF path, or any way to defeat a guarantee listed in SECURITY.md, please comment here or open a new issue. Credit given.
This is a v0 release: independently hardened (CodeQL, bandit, semgrep, property-based tests, adversarial tier 1-2 reviews, all green in CI) but not third-party audited. See SECURITY.md.
The shared crypto core (Ed25519 + RFC 8785 canonicalization) and the did:web SSRF guard are the highest-value targets.