-
Notifications
You must be signed in to change notification settings - Fork 161
Description
Hello, I am writing on behalf of my employer: https://curity.io/ (our former CEO, Travis, has previously contributed to this project).
We use java-webauthn-server in our product and wanted to ask a few questions about this project's dependencies.
As of version 2.6.0, this project depends on these libraries:
+--- com.upokecenter:cbor:4.5.6
| +--- com.github.peteroupc:numbers:1.8.2
| \--- com.github.peteroupc:datautilities:1.1.0
They do not seem to be owned by Yubico or any other related business, they are all authored by the same person: https://github.com/peteroupc
I could not find if there exists any relationship between them and Yubico, hence we would like to understand if you've been able to establish a trust relationship with them or verify their code.
As a fellow security company, we care deeply about our dependencies and hope that you do not mind us inquiring.
Thanks for your attention.