.gitbay/wiki/Architecture/10-Known-Gaps.org

3bcdce33fb9a2309312854331359d376171c7368
gitbay/.gitbay/wiki/Architecture/10-Known-Gaps.org rendered · source · history · blame · raw

35 lines · 2894 bytes

 1#+title: Known gaps
 2
 3Open weaknesses. Issues on krz/gitbay are public; this page gives the
 4title and the consequence, not a reproduction. The current list is the
 5open issues labelled =security=:
 6https://gitbay.org/krz/gitbay/issues?label=security. The table below is
 7what the 2026-09-27 review found; remove a row when its issue closes.
 8
 9* Filed
10
11| Issue | Area             | Gap                                                                   | Severity |
12|-------+------------------+-----------------------------------------------------------------------+----------|
13| #259  | Recovery         | No restore has been exercised; verification does not check git connectivity | high |
14| #260  | CI network       | Builds share the runner's source address; no egress policy            | medium   |
15| #261  | Various          | Migration foreign-key check after commit; three web writes bypass dispatch; documentation drift | medium |
16| #262  | Availability     | No limit on concurrent git pack generation                            | high     |
17| #273  | Data at rest     | CI secrets, webhook secrets and mirror tokens are stored in clear in SQLite | high |
18| #274  | Backups          | The local backup archive is not encrypted                             | medium   |
19| #298        | SSRF       | =repo import --from= fetches without an address check                 | medium   |
20| #297  | Credentials      | A browser session can mint tokens and keys that outlive it            | low      |
21
22* Not filed
23
24| Area  | Gap                                                                                                         | Severity |
25|-------+-------------------------------------------------------------------------------------------------------------+----------|
26| Audit | Removing the newest audit rows, or writing new rows under their freed ids, is not detectable from the database; only comparing =gitbayd admin audit verify='s last id and hash with the daemon's journal shows it. Rows written by =gitbayd shell= (=ssh.mode = "system"=) and host admin commands have no journal copy, and the refusal caps are per process, so under that mode each connection counts separately | low |
27
28* Questions an auditor will ask that have no answer yet
29
30| Question                                                  | Status                                   |
31|-----------------------------------------------------------+------------------------------------------|
32| What is the measured recovery time?                       | unmeasured (#259)                        |
33| How many concurrent clones does the host sustain?         | unmeasured (#262)                        |
34| What can a build reach on the host's network?             | configuration inspected, reachability untested (#260) |
35| Have the collaboration features been used by independent users? | no; one human user, tests only     |