NixOS/nixpkgs
a1e0b4ab0f2f
(1 day ago)
→
6a18e3b76092
(5 hours ago)
| Measure | Before | After | Change |
|---|---|---|---|
| Readiness score | 58 | 10 | -48 |
| Findings to address | 31 | 151 | +120 |
| Key establishment | 7 | 40 | +33 |
| Files scanned | 1872 | 46482 | +44610 |
Added
Present in the later scan and not in the earlier one.
| Finding | Assessment | Before | After |
|---|---|---|---|
Ed25519
SSH algorithms pinned in configuration · config.ssh-algorithms
|
Quantum-vulnerable | 0 | 28 |
RSASSA-PKCS1v15
SSH algorithms pinned in configuration · config.ssh-algorithms
|
Quantum-vulnerable | 0 | 11 |
ECDH
TLS cipher suite named in source · config.cipher-suite
|
Quantum-vulnerable | 0 | 7 |
X25519
SSH algorithms pinned in configuration · config.ssh-algorithms
|
Quantum-vulnerable | 0 | 7 |
DH
SSH algorithms pinned in configuration · config.ssh-algorithms
|
Quantum-vulnerable | 0 | 6 |
ECDH
SSH algorithms pinned in configuration · config.ssh-algorithms
|
Quantum-vulnerable | 0 | 6 |
RSA
SSH public key · ssh.public-key
|
Quantum-vulnerable | 0 | 4 |
RSASSA-PKCS1v15
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-vulnerable | 0 | 4 |
DSA
SSH algorithms pinned in configuration · config.ssh-algorithms
|
Quantum-vulnerable | 0 | 3 |
ECDSA
SSH algorithms pinned in configuration · config.ssh-algorithms
|
Quantum-vulnerable | 0 | 3 |
RSA
Public key file · pem.public-key
|
Quantum-vulnerable | 0 | 3 |
ECDSA
SSH public key · ssh.public-key
|
Quantum-vulnerable | 0 | 2 |
Ed25519
Private key committed to the repository · pem.private-key
|
Quantum-vulnerable | 0 | 2 |
ECDSA
Private key committed to the repository · pem.private-key
|
Quantum-vulnerable | 0 | 1 |
TLS
TLS cipher suites pinned in configuration · config.tls-ciphers
|
Quantum-vulnerable | 0 | 1 |
TLS
TLS versions pinned in configuration · config.tls-protocols
|
Quantum-vulnerable | 0 | 1 |
unknown
Private key committed to the repository · pem.private-key
|
Could not be determined | 0 | 9 |
unknown
X.509 certificate · pem.certificate
|
Could not be determined | 0 | 1 |
ML-KEM-768
SSH algorithms pinned in configuration · config.ssh-algorithms
|
Quantum-safe | 0 | 7 |
CSPRNG
Random number generation · py.rng
|
Quantum-safe | 0 | 1 |
ML-DSA-44
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-safe | 0 | 1 |
Count changed
The same finding, in a different number of places.
| Finding | Assessment | Before | After |
|---|---|---|---|
Ed25519
SSH public key · ssh.public-key
|
Quantum-vulnerable | 6 | 21 |
RSA
Private key committed to the repository · pem.private-key
|
Quantum-vulnerable | 4 | 9 |
ECDSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 5 | 6 |
Unchanged
9 findings appear in both scans, in the same number of places. Each scan's own report lists them.