Goal
Track remediation of the security findings identified in a static assessment of v0.1.0-alpha.20 (pinned commit 4ad2c10). Each finding was independently re-validated against the current code before filing, and each is filed as its own narrowly scoped issue. This is a tracking issue: it groups and orders the work but does not replace the linked issues. The definition of done for each item lives in its linked issue.
This release is a development pre-release, so these are remediation and hardening items for the v0.1.0 security baseline rather than reports against a supported release. See #132 (pre-v0.1.0 release validation) and #129 (graduate from alpha) for the surrounding release work.
All linked issues carry the area: security label.
Findings
Critical
High
Medium
Low
Notes
Goal
Track remediation of the security findings identified in a static assessment of
v0.1.0-alpha.20(pinned commit4ad2c10). Each finding was independently re-validated against the current code before filing, and each is filed as its own narrowly scoped issue. This is a tracking issue: it groups and orders the work but does not replace the linked issues. The definition of done for each item lives in its linked issue.This release is a development pre-release, so these are remediation and hardening items for the
v0.1.0security baseline rather than reports against a supported release. See #132 (pre-v0.1.0 release validation) and #129 (graduate from alpha) for the surrounding release work.All linked issues carry the
area: securitylabel.Findings
Critical
High
auth.groupsis documented as access control but is not enforced at the gatewayspaClient.clientIdcan reconfigure or delete an existing Keycloak clientMedium
generic-oidcissuerURLis unvalidated (gateway-side SSRF and client-secret exposure)Low
Notes
4ad2c10. The only intervening change to security-relevant files since then was landing-page icon fields, so the cited behavior is current.