.gitbay/wiki/Architecture/10-Known-Gaps.org

bd49b87fce895e9f0a7588152548fb6e1821ac7d
gitbay/.gitbay/wiki/Architecture/10-Known-Gaps.org rendered · source · history · blame · raw

32 lines · 2699 bytes

Known gaps

Open weaknesses. Issues on krz/gitbay are public; this page gives the title and the consequence, not a reproduction. The current list is the open issues labelled security: https://gitbay.org/krz/gitbay/issues?label=security. The table below is what the 2026-09-27 review found; remove a row when its issue closes.

Filed

Issue Area Gap Severity
#259 Recovery No restore has been exercised; the drill is written (Admin wiki) and not yet run high
#260 CI network Builds share the runner's source address; no egress policy medium
#261 Various Migration foreign-key check after commit; three web writes bypass dispatch; documentation drift medium
#297 Credentials A browser session can mint tokens and keys that outlive it low

Not filed

Area Gap Severity
Audit Removing the newest audit rows, or writing new rows under their freed ids, is not detectable from the database; only comparing gitbayd admin audit verify's last id and hash with the daemon's journal shows it. Rows written by gitbayd shell (ssh.mode = "system") and host admin commands have no journal copy, and the refusal caps are per process, so under that mode each connection counts separately low
Availability Under ssh.mode = "system" each SSH session is a separate gitbayd shell process, so the pack-generation limit (internal/packlimit, #262) cannot count SSH clones across sessions; only HTTP and git:// share a budget there low

Questions an auditor will ask that have no answer yet

Question Status
What is the measured recovery time? unmeasured (#259)
How many concurrent clones does the host sustain? unmeasured (#262)
What can a build reach on the host's network? configuration inspected, reachability untested (#260)
Have the collaboration features been used by independent users? no; one human user, tests only