Skip to content

Commit e246329

Browse files
committed
Add a contributors entry for the report of the unbounded decompressed size on the high-level OpenPGP message API.
1 parent a84c8df commit e246329

1 file changed

Lines changed: 1 addition & 0 deletions

File tree

‎CONTRIBUTORS.html‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -603,6 +603,7 @@
603603
<li>mauromol &lt;https://github.com/mauromol&gt; - reporting that RSASSA-PSS could not be used with a RIPEMD digest through the JCA API, tracing it to the missing PSS registrations and to DigestFactory.isSameDigest treating two identical non-SHA digest names as different (issue #2381) Reporting that EDIPartyName encoded its DirectoryString members without the RFC 5280 sec. 4.2.1.6 context tags its own decoder requires, so the type could not parse its own output (issue #2380).</li>
604604
<li>jmeeder &lt;https://github.com/jmeeder&gt; - reporting that RFC 4998 evidence-record generation rejected time stamps from an authority naming the digest with NULL parameters where BC names it with them absent, both of which RFC 5754 requires a receiver to accept (issue #2379).</li>
605605
<li>rimuln &lt;https://github.com/rimuln&gt; - diagnosis and fix for PKCS12 getCertificateAlias returning the alias of an unrelated certificate, tracing it to the alias and certificate enumerations of the keystore's certs table diverging in order once keys() enumerated a copy (issue #2384, PR #2385).</li>
606+
<li>Yu Bao &lt;yubao@paypal.com&gt; - reporting an API gap, on behalf of the PayPal Cyber Security Team, that the high-level OpenPGP message API (OpenPGPMessageProcessor / OpenPGPMessageInputStream) gave a caller no way to bound how far a compressed data packet expands, where the low-level PGPCompressedData it wraps has carried a bounded getDataStream(long) overload all along, and that OpenPGPPolicy exposed no equivalent property to set.</li>
606607
</ul>
607608
</body>
608609
</html>

0 commit comments

Comments
 (0)