tink-crypto/tink-java
4ef1628639b6
(5 days ago)
→
93ff48ee3c53
(2 hours ago)
| Measure | Before | After | Change |
|---|---|---|---|
| Findings to address | 307 | 312 | +5 |
| Quantum-vulnerable locations | 231 | 235 | +4 |
| Quantum-safe locations | 165 | 165 | - |
| Key establishment | 26 | 28 | +2 |
| Files scanned | 1373 | 1371 | -2 |
Added
Present in the later scan and not in the earlier one.
| Finding | Assessment | Before | After |
|---|---|---|---|
RSA-PSS
Classical signature algorithm through the JCA · java.signature
|
Quantum-vulnerable | 0 | 1 |
Count changed
The same finding, in a different number of places.
| Finding | Assessment | Before | After |
|---|---|---|---|
RSA
Classical key material handled through the JCA · java.keyfactory
|
Quantum-vulnerable | 12 | 13 |
RSA
Classical key pair generated through the JCA · java.keypairgenerator
|
Quantum-vulnerable | 2 | 3 |
RSA
Classical signature algorithm through the JCA · java.signature
|
Quantum-vulnerable | 8 | 9 |
SHA-256
Hash algorithm through the JCA · java.messagedigest
|
Reduced margin | 8 | 9 |
SHA-256
Mask-generation digest named for RSA padding · java.mgf1
|
Reduced margin | 1 | 2 |
Unchanged
49 findings appear in both scans, in the same number of places. Each scan's own report lists them.