Skip to content

chore: release 2.10.1#76

Merged
jagtejsodhi merged 1 commit into
mainfrom
release/update-binary-to-2.10.1
Apr 9, 2026
Merged

chore: release 2.10.1#76
jagtejsodhi merged 1 commit into
mainfrom
release/update-binary-to-2.10.1

Conversation

@privy-ios-sdk-release-bot

Copy link
Copy Markdown
Contributor

Automated PR to update PrivySDK.xcframework and podspec to version 2.10.1.

@semgrep-code-privy-io

Copy link
Copy Markdown

Semgrep found 7 ATS-consider-pinning findings:

  • PrivySDK.xcframework/macos-arm64_x86_64/dSYMs/PrivySDK.framework.dSYM/Contents/Info.plist
  • PrivySDK.xcframework/macos-arm64_x86_64/PrivySDK.framework/Versions/A/Resources/Info.plist
  • PrivySDK.xcframework/ios-arm64_x86_64-simulator/dSYMs/PrivySDK.framework.dSYM/Contents/Info.plist
  • PrivySDK.xcframework/ios-arm64_x86_64-maccatalyst/dSYMs/PrivySDK.framework.dSYM/Contents/Info.plist
  • PrivySDK.xcframework/ios-arm64_x86_64-maccatalyst/PrivySDK.framework/Versions/A/Resources/Info.plist
  • PrivySDK.xcframework/ios-arm64/dSYMs/PrivySDK.framework.dSYM/Contents/Info.plist
  • PrivySDK.xcframework/Info.plist

The application's App Transport Security (ATS) configuration does not leverage the in-built public key pinning mechanisms. The application should consider leverage ATS public key pinning to ensure that the application only communicates to serves with an allow-listed certificate (and public key). By default the device will allow connections if the default trust store (CA store) posesses the right certificates. The number of accepted Certificate Authorities by default is hundreds. Using public key pinning vastly reduces the attack surface.

@jagtejsodhi jagtejsodhi merged commit ce58569 into main Apr 9, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant