Skip to content

feat: Validate and pin peer encryption bundles - #9520

Open
rasswanth-s wants to merge 1 commit into
devfrom
rasswanth/fix-peer-key-pinning
Open

rasswanth-s wants to merge 1 commit into
devfrom
rasswanth/fix-peer-key-pinning

Conversation

@rasswanth-s

Copy link
Copy Markdown
Collaborator

Summary

A peer's public key bundle arrives over Drive, which the threat model treats
as adversarial, yet it was parsed without checking the DID it asserts and the
pin lived only in SYFT_peers.json on Drive, which load_peers re-read on every
sync. Anyone able to edit those bytes could swap the key and read "end-to-end"
encrypted traffic.

Changes

Testing

Adding Unit tests

Asana task

https://app.asana.com/1/1185126988600652/project/1210542925864934/task/1218392303871954


PR naming convention

Your PR title must follow this format or merging will be blocked:

type: short description in lowercase

Example titles:

  • feat: add retry logic to job approval
  • fix: handle timeout in notification sender
  • docs: update syft-bg README
  • chore: bump dependencies
  • refactor: split init flow into helpers
  • test: add criteria validation tests
  • ci: add release train workflow

Allowed types:

Type When to use Example
feat New feature or capability feat: add DS rejection emails
fix Bug fix fix: handle empty peer list
docs Documentation only docs: update syft-bg README
chore Maintenance, deps, config chore: bump dependencies
refactor Code restructuring (no behavior change) refactor: split init flow
test Adding or updating tests test: add approval criteria tests
ci CI/CD workflow changes ci: add release train workflow
perf Performance improvement perf: cache Drive API responses
build Build system or dependency changes build: pin syft-bg>=0.2.0

Just edit the PR title to fix any errors — the check re-runs automatically.

Auto-labeling

Labels are applied automatically — you don't need to add them manually:

  • Type labels from your PR title (e.g., feat: adds feature, fix: adds bugfix)
  • Package labels from which files you changed (e.g., editing packages/syft-bg/ adds pkg:syft-bg)

These labels are used to auto-generate categorized release notes.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant