docs: mark #28 security items done !29

merged merged by cmc on 2026-08-25 00:47 UTC · krz/gitbay:docs-28 into main

1 file changed, +12 −9

Layout: unified · split

docs/roadmap.org +12 −9
@@ -101,15 +101,18 @@ and the whole set gates flipping gitbay.org to open registration.
101 101
102- [[https://gitbay.org/krz/gitbay/issues/14][#14]] audit logging, rate limiting, quotas, user disable — the 102- [[https://gitbay.org/krz/gitbay/issues/14][#14]] audit logging, rate limiting, quotas, user disable — the
103 multi-user half 103 multi-user half
104- [[https://gitbay.org/krz/gitbay/issues/28][#28]] hardening umbrella — the rest, both layers: 104- [[https://gitbay.org/krz/gitbay/issues/28][#28]] hardening umbrella — concrete items done 2026-08-24
105 - software: fuzz all attacker-facing parsers (pkt-line, SSHSIG, 105 (umbrella stays open for ongoing work). Both layers landed:
106 commit, armor), web security headers (CSP et al.), govulncheck, 106 - software: fuzz targets for every attacker-facing parser (found and
107 constant-time comparison audit, a written threat model, signed 107 fixed a decodeArmor slice bug), CSP + security headers, govulncheck
108 releases 108 in =deploy/audit.sh= (fixed circl GO-2026-4550), token comparison
109 - host: unattended OS patching, tighter systemd sandboxing 109 audit (hash-lookup, no Go-level compare), =docs/threat-model.org=,
110 (SystemCallFilter and friends), auth throttling on both SSH 110 optional minisign over release manifests
111 surfaces, database file modes and continuous replication, 111 - host: systemd sandbox (=SystemCallFilter=@system-service=,
112 service/disk/cert monitoring 112 =PrivateDevices=, =LockPersonality=, =MemoryDenyWriteExecute=, …),
113 unattended-upgrades, fail2ban + =MaxStartups=/=MaxAuthTries= on the
114 admin sshd, hourly disk/service/cert monitoring; DB file modes 0750,
115 litestream noted for continuous replication. Applied to bay1.
113 116
114Already true and worth preserving (the threat model will write these 117Already true and worth preserving (the threat model will write these
115down): the forge never executes repository content; no server signing 118down): the forge never executes repository content; no server signing