Skip to content

Conversation

@MegaManSec
Copy link

This is a no-brainer patch that disallows multiple keys, of which one may contain a disallowed Algorithm (which will pass the validateSigningMethod call), from being validated. JSON serialization can carry multiple signatures with different headers/algorithms, which this validator does not intend to support.

…signature

Signed-off-by: Joshua Rogers <MegaManSec@users.noreply.github.com>
@MegaManSec MegaManSec requested a review from a team as a code owner October 29, 2025 06:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant