Skip to content

Update spdx_id generation to a FIPS compliant hash algorithm #1155

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
ctpham opened this issue Mar 20, 2025 · 0 comments
Open

Update spdx_id generation to a FIPS compliant hash algorithm #1155

ctpham opened this issue Mar 20, 2025 · 0 comments

Comments

@ctpham
Copy link

ctpham commented Mar 20, 2025

reuse.report is currently using MD5 to generate the spdx_id. Change this to a FIPS compliant algorithm.

Security Policy for FIPS 140-2 Validation See section 2.2 Non-Approved Algorithms

This will cause file digest read errors on a FIPS enabled OS.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant