
Security News
Crates.io Users Targeted by Phishing Emails
The Rust Security Response WG is warning of phishing emails from rustfoundation.dev targeting crates.io users.
@levischuck/tiny-cose
Advanced tools
A very incomplete COSE library for use with other tiny-*
libraries.
This implementation provides (incomplete):
CryptoKey
sCryptoKey
s into public and private
COSE key objectsCryptoKey
s into COSE key objectsThis implementation omits:
This implementation does not support:
CryptoKey
s for symmetric encryption with AESOver time, this list may change.
COSE cryptography is, in general, unsafe for most to dabble with. Please consult a cryptographer when you are inventing something new with cryptographic constructs.
FAQs
Tiny COSE library for cryptographic operations in CBOR
We found that @levischuck/tiny-cose demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
The Rust Security Response WG is warning of phishing emails from rustfoundation.dev targeting crates.io users.
Product
Socket now lets you customize pull request alert headers, helping security teams share clear guidance right in PRs to speed reviews and reduce back-and-forth.
Product
Socket's Rust support is moving to Beta: all users can scan Cargo projects and generate SBOMs, including Cargo.toml-only crates, with Rust-aware supply chain checks.