-
Notifications
You must be signed in to change notification settings - Fork 0
security: complete v1 beta security review #72
Copy link
Copy link
Open
Labels
area: authAuthentication, accounts, sessions, passkeys, and access control.Authentication, accounts, sessions, passkeys, and access control.area: runtimeOpenResty and privileged controller runtime behavior.OpenResty and privileged controller runtime behavior.securityPublic security hardening or remediation; disclose vulnerabilities privately.Public security hardening or remediation; disclose vulnerabilities privately.
Milestone
Description
Activity
Metadata
Metadata
Assignees
Labels
area: authAuthentication, accounts, sessions, passkeys, and access control.Authentication, accounts, sessions, passkeys, and access control.area: runtimeOpenResty and privileged controller runtime behavior.OpenResty and privileged controller runtime behavior.securityPublic security hardening or remediation; disclose vulnerabilities privately.Public security hardening or remediation; disclose vulnerabilities privately.
Summary
Perform the comprehensive security review before RentnerProxy enters
the v1 Beta phase.
This is a review + remediation issue, not a compliance certification.
Review Areas
Authentication
Authorization
Proxy Runtime
Access Policies
Certificates
Web/API
Files / Backup
GitHub / Supply Chain
Acceptance Criteria
Do NOT create a docs/security-report file unless repository policy
already requires one.
Priority
P0
Dependencies and sequencing
Initial review can start in parallel. Final review must include #64 and #65 if shipped, plus importer #66, upgrade #67 and backup/restore #71 changes. Review the existing runtime/access-policy foundations #19 and #28. Release-blocking findings must be resolved before #75 closes.
Report exploitable vulnerabilities and sensitive evidence through SECURITY.md; public tracking should contain sanitized findings and remediation status only.