Files
2026-09-28 14:49:00 -04:00

18 lines
705 B
Markdown

# Changelog
## 0.1.0 - 2026-09-28
First public release under MIT.
- `checkClaims()` and `formatClaims()` check advertised cryptographic claims
against the keys, ciphers and transport settings described.
- `end-to-end-encrypted` and `zero-knowledge` fail when a key is held by the
server, an operator or a third party, whatever the cipher strength.
- `encrypted-at-rest`, `encrypted-in-transit`, `passwords-hashed` and
`forward-secrecy` are each checked against the element that would enforce
them.
- Broken primitives (MD5, SHA-1, DES, 3DES, RC4, ECB) are reported even when
nothing was claimed about them.
- A claim with nothing describing it is reported as not assessed, never as a
pass.