soatok@furry.engineer ("Soatok Dreamseeker") wrote:
I've used GitHub's automation to request a CVE: https://github.com/soatok/constant-time-js/security/advisories/GHSA-pgf9-4q65-hrqj
There is (to my knowledge) zero downstream usage of this library, as it only serves as an educational resource in how to implement algorithms in constant-time (though no guarantees can be made about the runtimes the algorithms run in).
But just in case someone's doing something non-public, the CVE automation should kick them into upgrading.