Known gaps
Open weaknesses. Issues on krz/gitbay are public; this page gives the
title and the consequence, not a reproduction. The current list is the
open issues labelled security:
https://gitbay.org/krz/gitbay/issues?label=security. The table below is
what the 2026-09-27 review found; remove a row when its issue closes.
Filed
| Issue |
Area |
Gap |
Severity |
| #259 |
Recovery |
No restore has been exercised; verification does not check git connectivity |
high |
| #260 |
CI network |
Builds share the runner's source address; no egress policy |
medium |
| #261 |
Various |
Migration foreign-key check after commit; three web writes bypass dispatch; documentation drift |
medium |
| #262 |
Availability |
No limit on concurrent git pack generation |
high |
| #298 |
SSRF |
repo import --from fetches without an address check |
medium |
| #297 |
Credentials |
A browser session can mint tokens and keys that outlive it |
low |
Not filed
| Area |
Gap |
Severity |
| Audit |
Removing the newest audit rows, or writing new rows under their freed ids, is not detectable from the database; only comparing gitbayd admin audit verify's last id and hash with the daemon's journal shows it. Rows written by gitbayd shell (ssh.mode = "system") and host admin commands have no journal copy, and the refusal caps are per process, so under that mode each connection counts separately |
low |
Questions an auditor will ask that have no answer yet
| Question |
Status |
| What is the measured recovery time? |
unmeasured (#259) |
| How many concurrent clones does the host sustain? |
unmeasured (#262) |
| What can a build reach on the host's network? |
configuration inspected, reachability untested (#260) |
| Have the collaboration features been used by independent users? |
no; one human user, tests only |