.gitbay/wiki/Architecture/10-Known-Gaps.org

9df917e73a67d15adecc3f45976690f6fcd4e47a
gitbay/.gitbay/wiki/Architecture/10-Known-Gaps.org rendered · source · history · blame · raw

33 lines · 2668 bytes

Known gaps

Open weaknesses. Issues on krz/gitbay are public; this page gives the title and the consequence, not a reproduction. The current list is the open issues labelled security: https://gitbay.org/krz/gitbay/issues?label=security. The table below is what the 2026-09-27 review found; remove a row when its issue closes.

Filed

Issue Area Gap Severity
#259 Recovery No restore has been exercised; verification does not check git connectivity high
#260 CI network Builds share the runner's source address; no egress policy medium
#261 Various Migration foreign-key check after commit; three web writes bypass dispatch; documentation drift medium
#262 Availability No limit on concurrent git pack generation high
#298 SSRF repo import --from fetches without an address check medium
#297 Credentials A browser session can mint tokens and keys that outlive it low

Not filed

Area Gap Severity
Audit Removing the newest audit rows, or writing new rows under their freed ids, is not detectable from the database; only comparing gitbayd admin audit verify's last id and hash with the daemon's journal shows it. Rows written by gitbayd shell (ssh.mode = "system") and host admin commands have no journal copy, and the refusal caps are per process, so under that mode each connection counts separately low

Questions an auditor will ask that have no answer yet

Question Status
What is the measured recovery time? unmeasured (#259)
How many concurrent clones does the host sustain? unmeasured (#262)
What can a build reach on the host's network? configuration inspected, reachability untested (#260)
Have the collaboration features been used by independent users? no; one human user, tests only