Threat-Model wiki page omits the runner #138

closed cmc opened this on 2026-09-03 05:18 UTC · docs security · milestone v1.9.0

Discussion

cmc 2026-09-03 05:18 UTC

The page covers tokens, hashes, HMAC and the no-server-key rule, and says nothing about what executes repository content, as what, and where. Same gap as the runner issue.

cmc 2026-09-03 21:43 UTC

Threat-Model now has a section on the CI runner (what the runner holds, what a build sees, where it runs, and the accepted residual risk of uncontained steps), and Admin's runner section covers the runner key scope, the bootstrap flow, the sandboxing drop-in, untrusted fork builds, and trusted_proxies. Wiki commit e977337.