Upload the Trail of Bits public security assessment report#94
Upload the Trail of Bits public security assessment report#94SteveLasker merged 2 commits intoveraison:mainfrom
Conversation
Signed-off-by: Evan Sultanik <evan.sultanik@trailofbits.com>
c2064ca to
535a715
Compare
Codecov Report
@@ Coverage Diff @@
## main #94 +/- ##
==========================================
+ Coverage 89.48% 89.78% +0.29%
==========================================
Files 10 10
Lines 1018 1018
==========================================
+ Hits 911 914 +3
+ Misses 72 69 -3
Partials 35 35
Help us with your feedback. Take ten seconds to tell us how you rate us. |
|
Thanks @ESultanik, Page 11 Page 19 r/The veraison/go-cose library is a work in progress with continuous development. Trail of Bits recommends the veraison project address the findings detailed in this report and take the following additional steps prior to deployment: |
|
No problem, we will update the report and tag you here when it's ready. |
Signed-off-by: Evan Sultanik <evan.sultanik@trailofbits.com>
|
@SteveLasker I just pushed an updated version of the report. I didn't rebase this branch, so the old version is still in the git history. Let me know if you'd rather I do a rebase. |
SteveLasker
left a comment
There was a problem hiding this comment.
Thanks, @ESultanik for the updates and to the Trail of Bits team for the thorough review.
Adds a copy of the public report published at https://github.com/trailofbits/publications/blob/master/reviews/Microsoft-go-cose.pdf