Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SECURITY: Update paragonie/random_compat to 2.x minimum #1223

Merged
merged 1 commit into from
Mar 1, 2018

Conversation

kaystrobach
Copy link
Contributor

@kaystrobach kaystrobach commented Mar 1, 2018

The paragonie/random_compat library could use OpenSSL, and that in turn
could lead to the use of an insecure CSPRNG (openssl_random_pseudo_bytes())

Related Information: paragonie/random_compat#96

This change fixes #1222 by updating the dependency from ^1.0 to ^2.0.

@kdambekalns kdambekalns changed the title [SECURITY] Update paragonie/random_compat to 2.x SECURITY: Update paragonie/random_compat to 2.x minimum Mar 1, 2018
@kdambekalns kdambekalns merged commit 17ea27b into neos:3.3 Mar 1, 2018
@kaystrobach kaystrobach deleted the patch-3 branch March 1, 2018 09:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants