Coming from you I expect no silly questions. 😀 Will take a look in the AM if the European folks don’t first.
Профиль
Kevin Jones
Alexandria, VA. He / they Product Security and Cryptography at GitHub / Microsoft. .NET maintainer. Not speaking for my employer. https://vcsjones.dev ⚫️ https://gh.io/vcsjones
1,5 тыс. подписчиков205 подписок3 тыс. постов
Публикации
⟳ Репост от Kevin Jones
I'm seeing folks draw the wrong conclusion (in good faith or not) from the HAWK attack. HAWK is a scheme that 1. cryptographers were suspicious of and 2. was still in the assessment process. A break is GOOD. It means the process is useful, and it INCREASES confidence in the selected algorithms.
Yeah I don’t know what or how this could be figured out by default but I would look at the config for grouping options. One PR per dependency is painful. docs.github.com/en/code-secu...
eg here’s an AzureSignTool depebdabot PR that updates all System.* packages in one go. github.com/vcsjones/Azu...