buttercup / buttercup-core

:tophat: The mighty NodeJS password vault
http://buttercup.pw/
MIT License
469 stars 57 forks source link

3rd Party Audit? #307

Closed zicklag closed 3 years ago

zicklag commented 3 years ago

Hey folks! Just found buttercup and I'm really liking it so far! Great job.

I wanted to know whether or not you guys have gotten a 3rd party security audit or not, or if one is planned in the future.

perry-mitchell commented 3 years ago

Hi @zicklag - This has been asked before, but the answer is unfortunately no.

As with the other answer, audits cost money and right now Buttercup is receiving some small amount of donations that, while incredibly useful for hosting etc., are probably insufficient to pay for an audit.

If there are any that stand out, and are somewhat affordable, I'd gladly look into them.

zicklag commented 3 years ago

I totally understand, just wanted to make sure I wasn't missing anything.

For what it's worth, what little bit I've looked around your code I found it very readable which is definitely confidence inspiring for me, so I like that!

perry-mitchell commented 3 years ago

Thanks @zicklag - much appreciated.

All that having been said, I've just now put out a couple of contact requests to some auditing firms I've found.. let's see what they say and what they'd charge. Here's hoping!