-
-
Notifications
You must be signed in to change notification settings - Fork 56
Open
Description
Some security scan on our app points to that (js) api and reports that it is a weak random number generator. It also reports that there are better alternatives like using crypto.randomBytes().
Would want to know if this module's operation is security-critical in any way and specifically how those variables which are assigned values from expressions using Math.random() actually used.
wisekaa03, adryd325, cativo23 and Ice1984m
Metadata
Metadata
Assignees
Labels
No labels