floating / frame

System-wide Web3 for macOS, Windows and Linux

Home Page:https://frame.sh

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Security issue: hdkey package

paulmillr opened this issue · comments

It's pretty old and uncool. Uses a lot of sub-deps. Unaudited subdeps which could be updated by different authors is a supply chain security issue.

The suggestion is to switch to https://github.com/paulmillr/scure-bip32 which is being used by ethereum-cryptography in your dep tree. Scure has been audited, paid for by EF.

bip39 could also be replaced with scure-bip39.

commented

duplicate of #1526

not really a duplicate, more an extension: hdkey != bip39

commented

I feel like the priority of this should be bumped