chore: bump starknet-crypto to v0.6.1 #1469
Merged
+7
−14
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Update
starknet-crypto
Description
The new version contains a bug fix on ECDSA signature verification. Previously, the
s
range was incorrectly enforced to be lower than EC order instead of element bound. While this did not allow invalid signatures to be used, it was theoretically possible (1 in 2^48 signatures) to have a signature that passesverify
yet cannot be proven (due to being out of element bound).This wouldn't be an issue though, as long as other parts of the VM already enforce the range, but I'm not sure if it's the case. But in any case it wouldn't be a bad thing to upgrade anyways.
Checklist