Commit aeedf75018
Verified · cmc ci/build: success ci/sonar: success ci/test: success ci/vuln: success
Layout: unified · split
.gitbay/wiki/Threat-Model.org +26
| @@ -141,6 +141,32 @@ Treat the runner host as executing untrusted code: keep it off the | |||
| 141 | daemon's host where the database lives, or scope it to repositories | 141 | daemon's host where the database lives, or scope it to repositories |
| 142 | whose writers you trust. | 142 | whose writers you trust. |
| 143 | 143 | ||
| 144 | * What has not been audited | ||
| 145 | |||
| 146 | The 2026-09 sweep (krz/gitbay#149) read this repository against the | ||
| 147 | claims above. Its two findings — review verdicts from accounts without | ||
| 148 | write access deciding merge gates (#147), and control commands having no | ||
| 149 | write rate limit while the API had one (#148) — are fixed, as is #173, | ||
| 150 | found afterwards in the same milestone. What it did not reach, and why, | ||
| 151 | is recorded here rather than in a closed issue: | ||
| 152 | |||
| 153 | - *The host.* systemd sandboxing, sshd on 2222, the firewall, | ||
| 154 | unattended-upgrades, fail2ban, disk and file modes, restic append-only | ||
| 155 | credentials. Reading production configuration is a separate exercise | ||
| 156 | from auditing the source, and needs doing against bay1. | ||
| 157 | - *The supply chain beyond =govulncheck=.* No review of what the | ||
| 158 | dependency set is, who maintains it, or what a compromised release of | ||
| 159 | any of it would reach. | ||
| 160 | - *The runner host as an execution environment.* Nobody has tried to | ||
| 161 | escape what is there. #144 covers the missing isolation. | ||
| 162 | - *Timing and traffic analysis.* Token comparison is a hash index lookup | ||
| 163 | by design, but nothing has been measured. | ||
| 164 | - *Denial of service by resource exhaustion* beyond rate: large pushes, | ||
| 165 | pathological diffs, deep histories, zip bombs in LFS. | ||
| 166 | |||
| 167 | A sweep is a point in time. This section says what a reader should not | ||
| 168 | assume has been checked. | ||
| 169 | |||
| 144 | * Residual risks, accepted | 170 | * Residual risks, accepted |
| 145 | 171 | ||
| 146 | - External images in rendered READMEs and profile about text load from | 172 | - External images in rendered READMEs and profile about text load from |