Repositorio
golang/crypto
Escaneado el 4 jun 2026
Puntuación de riesgo/ 100
Riesgo alto
Resumen
The golang/crypto repository contains widespread use of quantum-vulnerable cryptographic algorithms across 58 files with 315 total findings. Critical issues include broken algorithms (MD5, SHA-1) in 60 instances and quantum-vulnerable primitives (ECDSA, RSA, ECDH) in 234 instances. Immediate migration to NIST-approved post-quantum algorithms is required for compliance with emerging regulations.
60
140
0
0
Hallazgos principales
- CríticoMD5
ocsp/ocsp_test.go:249
SHA3-256 or SHA-256
Evidencia
template.IssuerHash = crypto.MD5 - CríticoMD5
ocsp/ocsp_test.go:252
SHA3-256 or SHA-256
Evidencia
t.Fatal("CreateResponse didn't fail with non-valid template.IssuerHash value crypto.MD5") - CríticoSHA-1
ocsp/ocsp_test.go:260
SHA-256 or SHA3-256
Evidencia
{"crypto.SHA1", crypto.SHA1}, - CríticoSHA-1
openpgp/clearsign/clearsign_test.go:256
SHA-256 or SHA3-256
Evidencia
Hash: SHA1 - CríticoMD5
openpgp/s2k/s2k.go:239
SHA3-256 or SHA-256
Evidencia
{1, crypto.MD5, "MD5"},
+ 195 hallazgos más en el reporte completo
Escanea tu propio repositorio
Gratis. Resultados en ~90 segundos. CBOM + PDF DORA/NIS2 incluidos.