[Pkg-javascript-devel] Bug#860939: node-diffie-hellman: Please clarify security concerns

Pirate Praveen praveen at debian.org
Sat Mar 17 12:18:58 UTC 2018


On Sun, 23 Apr 2017 14:58:58 +0200 roucaries bastien
<roucaries.bastien+debian at gmail.com> wrote:
> control: forwarded -1
> https://github.com/crypto-browserify/diffie-hellman/issues/22

Since there is no progress on this upstream, I think removing dh support
is the way to go. Since this implementation is insecure, no package
should depend on this functionality anyway.

See if this is okay.
https://anonscm.debian.org/cgit/pkg-javascript/node-crypto-browserify.git/log/?h=remove-dh

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 862 bytes
Desc: OpenPGP digital signature
URL: <http://lists.alioth.debian.org/pipermail/pkg-javascript-devel/attachments/20180317/6b0b47d7/attachment.sig>


More information about the Pkg-javascript-devel mailing list