TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Tips for finding security issues in GitHub projects

115 点作者 geekrax超过 7 年前

3 条评论

latchkey超过 7 年前
Thanks for sharing! Seems like a company that does this as an automated service (for private orgs/repos) would be $.
评论 #15422734 未加载
_asummers超过 7 年前
What does the author mean about timing attacks on HMACs with Array.equals? Does HMAC leak info and is it subject to timing attacks if you HMAC on both sides before doing equality checks? Does he mean for e.g. session cookies?
评论 #15423647 未加载
reconbot超过 7 年前
Some of the links are bad but this is a great list of things to keep in mind when seeing where your work is with regards to security.