smallstep/certificates
fa946c527a6c
(9 days ago)
→
f35d82e63d0b
(3 hours ago)
| Measure | Before | After | Change |
|---|---|---|---|
| Findings to address | 895 | 902 | +7 |
| Quantum-vulnerable locations | 940 | 944 | +4 |
| Quantum-safe locations | 43 | 48 | +5 |
| Key establishment | 233 | 234 | +1 |
| Files scanned | 456 | 479 | +23 |
Added
Present in the later scan and not in the earlier one.
| Finding | Assessment | Before | After |
|---|---|---|---|
ECDSA
Algorithm named in a setting · config.algorithm-setting
|
Quantum-vulnerable | 0 | 3 |
ML-DSA-65
Post-quantum algorithm in use · go.pqc
|
Quantum-safe | 0 | 4 |
Resolved
Present in the earlier scan and gone in the later one.
| Finding | Assessment | Before | After |
|---|---|---|---|
ECDH
Key agreement in Go · go.ecdh
|
Quantum-vulnerable | 1 | 0 |
Count changed
The same finding, in a different number of places.
| Finding | Assessment | Before | After |
|---|---|---|---|
ECDH
TLS cipher suite named in source · config.cipher-suite
|
Quantum-vulnerable | 117 | 119 |
ECDSA
ECDSA in the Go standard library · go.ecdsa
|
Quantum-vulnerable | 40 | 42 |
ECDSA
ECDSA in the Go standard library · go.ecdsa
|
Quantum-vulnerable | 3 | 2 |
RSA
RSA in the Go standard library · go.rsa
|
Quantum-vulnerable | 2 | 1 |
RSA
RSA in the Go standard library · go.rsa
|
Quantum-vulnerable | 19 | 20 |
unknown
X.509 certificate handling · go.x509
|
Could not be determined | 13 | 15 |
Unchanged
44 findings appear in both scans, in the same number of places. Each scan's own report lists them.