semaphore-protocol / semaphore

A zero-knowledge protocol for anonymous interactions.
https://semaphore.pse.dev
MIT License
870 stars 187 forks source link

Improve security practices #787

Open sripwoud opened 1 month ago

sripwoud commented 1 month ago

See https://discord.com/channels/943612659163602974/1006997078259552346/1237782683229356173 (PSE internal discord).

Here are the scorecard results of the semaphore repo: 4.3/10 (scorecard.txt)

I don't think the goal is to get a 10/10. But there are probably some quick wins we can implement like:

See links in report for more explanation and mitigations

cedoor commented 1 month ago

Thank you very much for pointing this out @sripwoud! Super important 🙏🏽