The dependency scan reported 14 high/critical findings across the backend and the marketplace frontend. All of them are now closed, and the scan is green for the first time. **Bumped, with the suite as the check.** aiohttp 3.14.1 -> 3.14.3, pyasn1 0.6.3 -> 0.6.4, pydantic-settings 2.14.1 -> 2.15.0, and cryptography 48.0.1 -> 50.0.0. That last one crosses two majors, which is why it was flagged as blast radius rather than a routine bump; the full backend suite passes unchanged. nanoid and postcss in the marketplace frontend are patched and the frontend still builds. **ecdsa has no fix and never will.** CVE-2024-23342 is a Minerva timing attack on P-256, and the project considers side channels out of scope. It arrives through python-jose, and only signing, key generation and ECDH are affected — verification is not. The backend signs tenant tokens with the symmetric JWT_SECRET, so only HMAC families are coherent there anyway. That was true by habit, not by construction: `jwt_algorithm` had no validation at all, so JWT_ALGORITHM=ES256 would have signed through the vulnerable path with nothing to say so. app/core/security.py now refuses any algorithm outside HS256/HS384/HS512, on both the encode and decode paths, and tests/test_jwt_algorithm_guard.py fails if that control is removed. `none` is refused alongside ES*: an unsigned token is not a lesser problem than a badly signed one. The advisory is accepted by exact ID with that control named, using a mechanism added here rather than by silencing the tool. A new advisory on ecdsa still fails, and a package whose every finding is accepted stops being listed as vulnerable so the field keeps meaning something. Backend 1419 passed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
9 lines
273 B
AMPL
9 lines
273 B
AMPL
// A separate module on purpose: go.attesto.eu/sdk has no dependencies at all,
|
|
// and a consumer who never opens a private numeric should not inherit a curve
|
|
// library to keep it that way.
|
|
module go.attesto.eu/sdk/zk
|
|
|
|
go 1.24
|
|
|
|
require github.com/gtank/ristretto255 v0.1.2
|