|
|
Message-ID: <93ced2d4-3ec7-430b-816b-4e078a6c49f3@oracle.com>
Date: Mon, 13 Apr 2026 08:25:46 -0700
From: Alan Coopersmith <alan.coopersmith@...cle.com>
To: oss-security@...ts.openwall.com, Alexander Patrakov <patrakov@...il.com>
Subject: Re: Security Audit of Hex, the Erlang package manager
On 4/12/26 19:28, Alexander Patrakov wrote:
> Hello Alan,
>
> How am I, as a user, supposed to authenticate these PDFs as materials
> really produced by the parties Hex claims they are from? The PDFs are
> offered for download from the audited-party domain, not from the auditors'
> domains, and do not contain any digital signatures.
That'd be a question to ask the Hex people, not the unrelated person who
saw the reports online and brought them to this mailing list, but for at
least Paraxial, I can point out that I first learned about this audit
from their blog post at https://paraxial.io/blog/hex-pentest which I saw
shared in the OpenSSF slack forums.
--
-Alan Coopersmith- alan.coopersmith@...cle.com
Oracle Solaris Engineering - https://blogs.oracle.com/solaris
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.