
Security News
Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline, Forces Certificate Rotation
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.
compare the performance of various cryptoprimitives in [sodium](https://github.com/paixaop/node-sodium)
compare the performance of various cryptoprimitives in sodium
(by the way, using my secretbox_easy branch)
This runs a script that runs an operation as many times as possible within 1 second. The total operations is then output, along with the number of operations/second compared to a sha256 hash. (i.e, how many sha256 hashes you could have done in the time to perform one operation)
first asymmetric primitives are tested, and then encryption/decryption is tested for inputs of increasing size. (32, 1024, 8096, 1048576 bytes)
note that the time to fail to decrypt a box is also measured. (this means calculate the poly1305 one time auth, but not calculating the keystream)
MIT
FAQs
compare the performance of various cryptoprimitives in [sodium](https://github.com/paixaop/node-sodium)
We found that sodiumperf demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.

Security News
Open source is under attack because of how much value it creates. It has been the foundation of every major software innovation for the last three decades. This is not the time to walk away from it.

Security News
Socket CEO Feross Aboukhadijeh breaks down how North Korea hijacked Axios and what it means for the future of software supply chain security.