EPISODE · Aug 25, 2022 · 16 MIN
Episode 109 - Verify and Verify Again
from Two Voice Devs · host Mark and Allen
Making sure our #VoiceFirst applications are written securely and use secure components is important. And when one of those components has a security bug, it is important that we update it as soon as we can. Mark highlights a recent security vulnerability in the node-forge module, which is used by the alexa-verifier-middleware module. Mark and Allen then discuss what the verifier does and how we can be careful when it comes to using libraries. Some references: alexa-verifier-middleware: https://www.npmjs.com/package/alexa-verifier-middleware Alexa verification: https://developer.amazon.com/en-US/docs/alexa/custom-skills/host-a-custom-skill-as-a-web-service.html#manually-verify-request-sent-by-alexa Issues with node-forge: https://github.com/advisories/GHSA-x4jg-mjrx-434g
What this episode covers
Making sure our #VoiceFirst applications are written securely and use secure components is important. And when one of those components has a security bug, it is important that we update it as soon as we can. Mark highlights a recent security vulnerability in the node-forge module, which is used by the alexa-verifier-middleware module. Mark and Allen then discuss what the verifier does and how we can be careful when it comes to using libraries. Some references: alexa-verifier-middleware: https://www.npmjs.com/package/alexa-verifier-middleware Alexa verification: https://developer.amazon.com/en-US/docs/alexa/custom-skills/host-a-custom-skill-as-a-web-service.html#manually-verify-request-sent-by-alexa Issues with node-forge: https://github.com/advisories/GHSA-x4jg-mjrx-434g
NOW PLAYING
Episode 109 - Verify and Verify Again
No transcript for this episode yet
Similar Episodes
Apr 22, 2025 ·32m
Feb 27, 2025 ·0m
Sep 20, 2024 ·57m
Aug 7, 2024 ·16m