Skip to content

Pentesting page on our website #82

@teon

Description

@teon

We need a design (unfortunately under current website) of a "pentesting" subpage.
The page should:

  • Have the same menu on top - but the rest can be done with NEWish design ;D
  • First there needs to be an explenation:
Defguard is truly open not only (code)[https://github.com/defguard/defguard], but our development process, roadmaps and... all detailed penetration testing reports our [security team - ISEC](https://isec.pl) finds during periodically done detailed security audits of all Defguard components.
Here you can find all previews and current reports, as well as links to Pull Requiests for each finding, fixing the issue.
  • Then there should be latest pentest section that has:
    • Date of the penetration tests
    • Version of components that were tested (eg. Core 1.5.0, proxy 1.5.0, Desktop Client 1.5.0, Gateway 1.5.0, Mobile 1.0)
    • Link to the PDF reports to download the original reports (Server, Mobile, Desktop - may be 1 to 3)
    • list of issues on the left? eg. issue: DG25-25: Access token is not being revoked when OpenID app becomes disabled
    • when clicking on this on the right panel there should be details of the issue that will be markdown and have: text, code snipplets, screenshots, can be long depending (see the report for examples)
      • There will be section in details of description of the issue and then recommended steps to fix it
    • there should be a visible (most important link) to the Pull Request on GitHub that fixes the issue
  • Below can be previous reports - but they should be "hidden" (same as above)
  • There could also be a link to our security page /security/ with information: Here you can find how we approach security in Defguard
  • There should be also a visible (somehere?) button? to our Vulnerability Disclosure Process: https://defguard.net/security/#VDP-title

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Status

Ready to release

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions