constant-time-analysis
Warn
Audited by Socket on May 6, 2026
1 alert found:
AnomalyAnomalyct_analyzer/tests/test_samples/decompose_vulnerable.go
LOWAnomalyLOW
ct_analyzer/tests/test_samples/decompose_vulnerable.go
No evidence of overt supply-chain malware (no exfiltration/backdoor/system interaction). However, the code is intentionally written to be variable-time: it uses input-derived integer division/modulo and branches on intermediate values (r0, hint). This makes it unsafe for production or any constant-time/side-channel-resistant cryptographic use; its key risk is timing side-channel leakage due to non-constant-time control flow and operations.
Confidence: 84%Severity: 66%
Audit Metadata