cloudflare/cfssl
e429e72785df
(5 days ago)
→
82408a199099
(2 hours ago)
| Measure | Before | After | Change |
|---|---|---|---|
| Findings to address | 1798 | 1457 | -341 |
| Quantum-vulnerable locations | 1521 | 1196 | -325 |
| Quantum-safe locations | 40 | 41 | +1 |
| Key establishment | 458 | 463 | +5 |
| Files scanned | 553 | 562 | +9 |
Added
Present in the later scan and not in the earlier one.
| Finding | Assessment | Before | After |
|---|---|---|---|
CSPRNG
Random number generation · go.rng
|
Quantum-safe | 0 | 7 |
HMAC
Keyed hash in use · go.hmac
|
Quantum-safe | 0 | 4 |
Count changed
The same finding, in a different number of places.
| Finding | Assessment | Before | After |
|---|---|---|---|
RSA-1024
X.509 certificate · pem.certificate
|
Already broken | 118 | 104 |
RSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 300 | 131 |
RSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 568 | 455 |
ECDSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 83 | 39 |
ECDSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 22 | 16 |
RSA
Private key committed to the repository · pem.private-key
|
Quantum-vulnerable | 30 | 35 |
ECDSA
ECDSA in the Go standard library · go.ecdsa
|
Quantum-vulnerable | 4 | 5 |
ECDSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 5 | 4 |
RSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 3 | 2 |
RSA
Private key committed to the repository · pem.private-key
|
Quantum-vulnerable | 5 | 4 |
TLS
TLS configuration in code · go.tls.config
|
Quantum-vulnerable | 25 | 26 |
unknown
X.509 certificate handling · go.x509
|
Could not be determined | 22 | 23 |
Unchanged
45 findings appear in both scans, in the same number of places. Each scan's own report lists them.