krz/gitbay
label: security clear
milestones · labels
quotas for organizations: orgs per user, repos and bytes per org security
#325 opened by cmc · in hosting
limits: bound concurrent pushes; put repo download under the pack limit security
#308 opened by cmc
mail: verify DKIM on reply mail in gitbayd instead of relying on Authentication-Results security
#307 opened by cmc
store: ids are reused after a hard delete; audit signed values that name them security
#306 opened by cmc
backup: prove the off-host secret.key opens a restored database security
#305 opened by cmc
lfs: transfer tokens outlive the revoked key keys security
#285 opened by cmc
webhook add takes the secret on argv control security
#284 opened by cmc
hookd: restrict and authenticate the hook socket control security
#282 opened by cmc
https: set the TLS minimum version explicitly ops security
#281 opened by cmc
mail: option to require TLS to the relay ops security
#280 opened by cmc
mirror: re-check the address at sync time ops security
#279 opened by cmc
web login over SSH skips the login-link rate limit security web
#278 opened by cmc
keys: optional expiry for SSH and deploy keys keys security
#277 opened by cmc
web: idle timeout for browser sessions security web
#276 opened by cmc
audit: record refused writes; make the log tamper-evident admin security
#275 opened by cmc
backup: local archives are not encrypted ops security
#274 opened by cmc
Secrets stored in clear in SQLite (CI secrets, webhook secrets, mirror tokens) security store
#273 opened by cmc
git: limit concurrent pack generation across HTTP and SSH ops security
#262 opened by cmc
runner: separate the runner's source address from its builds; egress policy ci ops security
#260 opened by cmc
ci: reserve ci/* statuses for the runner; tree reuse excludes untrusted builds ci mr security
#258 opened by cmc
token: expiring tokens cannot mint credentials; record creator; default read scope control migration security
#257 opened by cmc
sshd: removing a key closes its connections keys priority security
#256 opened by cmc
runner: disposable HOME for untrusted builds ci priority security
#255 opened by cmc
SonarCloud: 38 open, four worth fixing security
#238 opened by cmc
Removing an org member leaves their team membership and grants bug orgs security
#196 opened by cmc
No test enforces that every mutating route carries checkOrigin security
#157 opened by cmc · in v1.14.0
Nothing pins the login() disabled guard, or SetUserDisabled at all security
#156 opened by cmc · in v1.14.0
SonarCloud first scan: five valid findings security
#153 opened by cmc · in security
Security sweep 2026-09: what was covered, and what was not security
#149 opened by cmc · in security
SSH control commands have no write rate limit; the JSON API has one security
#148 opened by cmc · in security
Review verdicts from accounts without write access satisfy and block merge gates security
#147 opened by cmc · in security
Runner has no isolation, so a build runs as the runner's user security
#144 opened by cmc · in v1.14.0
Shutdown waits on idle SSH connections, and a restart locks the CLI out via the auth rate limit cli ops security
#141 opened by cmc · in v1.10.0
Threat-Model wiki page omits the runner docs security
#138 opened by cmc · in v1.9.0
Rate limit keys by RemoteAddr, email add is unthrottled, repo owner has no foreign key ops security
#136 opened by cmc · in v1.9.0
Git subprocess arguments are not -- terminated security
#135 opened by cmc · in v1.9.0
Admin gating and ReadsStdin are per-handler conventions with no test control security
#127 opened by cmc · in v1.9.0
git archive has no timeout or size cap ops security
#124 opened by cmc · in v1.9.0
HTTP server has no timeouts ops security
#104 opened by cmc · in v1.9.0
Pre-receive with require_signed_commits forks one process per commit ops security
#100 opened by cmc · in v1.12.0
CODEOWNERS is only enforced when required approvals is above zero bug mr security
#99 opened by cmc · in v1.9.0
ReadOnly is one flag with four consequences and no test control security
#97 opened by cmc · in v1.9.0
Disabled accounts keep working over the API and web bug security
#95 opened by cmc · in v1.9.0
CI runner executes untrusted repository code as the instance admin bug ci priority security
#92 opened by cmc · in v1.9.0
web sessions: list and revoke security
#83 opened by cmc · in v1.7.0
quotas for open registration and expiry of pending accounts security
#82 opened by cmc · in v1.7.0
audit: filters and --json on the host-local command admin security
#73 opened by cmc · in v1.4.0
admin: explicit, audited override on repositories for moderation admin security
#71 opened by cmc · in v1.4.0
admin: promote and demote instance admins admin security
#70 opened by cmc · in v1.4.0
security hardening: remaining items roadmap security
#28 opened by cmc
older →