Recent Advisories

Severity ID Title Vendor Product Date Type
NONE FILIPPOIO:A4CFF...

Quantum Computers Are Not a Threat to 128-bit Symmetric Keys_FILIPPOIO:A4CFF6D61CB110EED00826901925D2C7

The advancing threat of cryptographically-relevant quantum computers has made it urgent to replace currently-deployed asymmetric cryptography primi...

N/A N/A FILIPPOIO
MEDIUM 6.3 FILIPPOIO:E9AFE...

Turn Dependabot Off_FILIPPOIO:E9AFE970A5EB71BD3D5CD46EA35EEC57

Dependabot is a noise machine. It makes you feel like you’re doing work, but you’re actually discouraging more useful work. This is _especially_ tr...

N/A N/A FILIPPOIO
NONE FILIPPOIO:4C3AC...

Inspecting the Source of Go Modules_FILIPPOIO:4C3AC46D92115FA237F1DB3D5895A1B6

Go has indisputably the best package integrity story of any programming language ecosystem. The Go Checksum Database guarantees that every Go clien...

N/A N/A FILIPPOIO
NONE FILIPPOIO:21849...

go.sum Is Not a Lockfile_FILIPPOIO:2184996B45FE9BE864E32BEC8C2ADC1F

I need everyone to stop looking at `go.sum`, _especially_ to analyze dependency graphs. It is not a “lockfile,” and it has zero semantic effects on...

N/A N/A FILIPPOIO
NONE FILIPPOIO:964EA...

Building a Transparent Keyserver_FILIPPOIO:964EA4027160A9325BFD57EFDFBC420B

Today, we are going to build a keyserver to lookup age public keys. That part is boring. What’s interesting is that we’ll apply the same transparen...

N/A N/A FILIPPOIO
NONE FILIPPOIO:F5DD1...

The 2025 Go Cryptography State of the Union_FILIPPOIO:F5DD12F1301AA8A0231AA14F7EE79674

Last August, I delivered my traditional _Go Cryptography State of the Union_ talk at GopherCon US 2025 in New York. It goes into everything that h...

N/A N/A FILIPPOIO
NONE FILIPPOIO:4B0E0...

Claude Code Can Debug Low-level Cryptography_FILIPPOIO:4B0E04D990771751784DE1A55F1CB2E0

Over the past few days I wrote a new Go implementation of ML-DSA, a post-quantum signature algorithm specified by NIST last summer. I livecoded it ...

N/A N/A FILIPPOIO
NONE FILIPPOIO:1B3C5...

The Geomys Standard of Care_FILIPPOIO:1B3C53923EE685A2EE6484DE7927D61A

One of the most impactful effects of professionalizing open source maintenance is that as professionals we can invest into upholding a set of stand...

N/A N/A FILIPPOIO
NONE FILIPPOIO:12633...

A Retrospective Survey of 2024/2025 Open Source Supply Chain Compromises_FILIPPOIO:12633262B361F59CF582F3010928BD7A

Lack of memory safety is such a predominant cause of security issues that we have a responsibility as professional software engineering to robustly...

N/A N/A FILIPPOIO
MEDIUM 6 FILIPPOIO:F563E...

Maintainers of Last Resort_FILIPPOIO:F563E51346B142875A0AA33552E9FA3D

Geomys is an organization of professional open source maintainers, focused on a portfolio of critical Go projects. For example, we are two thirds o...

N/A N/A FILIPPOIO