[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

A note on in JSON changelog/sigantures



This is one of the reasons I'm opposed to in JSON changelog/signatures and instead would just rather use git commits/notes and signatures:

https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations

TL;DR: any spec like this will let people do things a bit differently and thus wrong. 

--

Kurt Seifried -- Red Hat -- Product Security -- Cloud
PGP A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993
Red Hat Product Security contact: secalert@redhat.com

Page Last Updated or Reviewed: February 27, 2018