box / box/box-java-sdk

Increase hashing capabilities from SHA1(vulnerable) to SHA256 or higher

未关闭
#1,041 2 条评论 0 个 reaction 已指派 4 人 已被 @mwwoda 认领 在 GitHub 查看
enhancement
主要语言
Java
星标
170
派生
189
平均合并
20 小时 26 分钟
30 天内合并 PR
22

描述

### Is your feature request related to a problem? Please describe.

It has been made clear by the industry at IBM that SHA1 is suspect in its partial security weaknesses and causes applications that use the box sdk to fail app scan testing as the box sdk is not secure enough and needs safer hashes.
### Describe the solution you'd like

Box needs to add SHA256 and SHA512 compatibility so the sdk can be classified as safe and not cause vulnerabilities for companies such as IBM that use the sdk
### Describe alternatives you've considered

No clear alternative yet as my entire application works on the box sdk
### Additional context

This is a high priority item and should be remedied as soon as possible to make the box sdk secure again

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。