wiki: record what the security sweep did not cover !286

merged merged by cmc on 2026-09-06 18:49 UTC · krz/gitbay:sweep-149 into main

1 file changed, +26 −0

Layout: unified · split

.gitbay/wiki/Threat-Model.org +26
@@ -141,6 +141,32 @@ Treat the runner host as executing untrusted code: keep it off the
141141daemon's host where the database lives, or scope it to repositories
142142whose writers you trust.
143143
144* What has not been audited
145
146The 2026-09 sweep (krz/gitbay#149) read this repository against the
147claims above. Its two findings — review verdicts from accounts without
148write access deciding merge gates (#147), and control commands having no
149write rate limit while the API had one (#148) — are fixed, as is #173,
150found afterwards in the same milestone. What it did not reach, and why,
151is recorded here rather than in a closed issue:
152
153- *The host.* systemd sandboxing, sshd on 2222, the firewall,
154 unattended-upgrades, fail2ban, disk and file modes, restic append-only
155 credentials. Reading production configuration is a separate exercise
156 from auditing the source, and needs doing against bay1.
157- *The supply chain beyond =govulncheck=.* No review of what the
158 dependency set is, who maintains it, or what a compromised release of
159 any of it would reach.
160- *The runner host as an execution environment.* Nobody has tried to
161 escape what is there. #144 covers the missing isolation.
162- *Timing and traffic analysis.* Token comparison is a hash index lookup
163 by design, but nothing has been measured.
164- *Denial of service by resource exhaustion* beyond rate: large pushes,
165 pathological diffs, deep histories, zip bombs in LFS.
166
167A sweep is a point in time. This section says what a reader should not
168assume has been checked.
169
144170* Residual risks, accepted
145171
146172- External images in rendered READMEs and profile about text load from