-
Notifications
You must be signed in to change notification settings - Fork 43
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
create_task binds caller-supplied repo_id/assignee_did verbatim, allowing task injection under foreign repo ids
kind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:identityDID/UCAN, http-sig auth, push authorizationDID/UCAN, http-sig auth, push authorizationStatus: Open.#496 In Twigpine/node;gl(mcp): ucan_delegate panics on overflow expiry and ucan_verify ignores nbf
crate:glgl — the contributor CLIgl — the contributor CLIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:mediumDegraded but workaround existsDegraded but workaround existssubsystem:identityDID/UCAN, http-sig auth, push authorizationDID/UCAN, http-sig auth, push authorizationStatus: Open.#494 In Twigpine/node;gl: unencoded path and query segments flow into signed requests
crate:glgl — the contributor CLIgl — the contributor CLIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:mediumDegraded but workaround existsDegraded but workaround existssubsystem:apiNode REST API request/response surfaceNode REST API request/response surfaceStatus: Open.#493 In Twigpine/node;gl(name): on-chain name and DID registries accept registrations without proving control of the DID
crate:glgl — the contributor CLIgl — the contributor CLIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:identityDID/UCAN, http-sig auth, push authorizationDID/UCAN, http-sig auth, push authorizationStatus: Open.#492 In Twigpine/node;gl: quickstart and init silently regenerate an unreadable identity, orphaning the agent DID
crate:glgl — the contributor CLIgl — the contributor CLIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:identityDID/UCAN, http-sig auth, push authorizationDID/UCAN, http-sig auth, push authorizationStatus: Open.#491 In Twigpine/node;api(arweave): negative limit reaches SQL LIMIT and surfaces as 503 db_unavailable
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-havesubsystem:apiNode REST API request/response surfaceNode REST API request/response surfaceStatus: Open.#490 In Twigpine/node;graphql(ws): Lagged errors are swallowed, so slow subscribers silently miss events
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:mediumDegraded but workaround existsDegraded but workaround existssubsystem:apiNode REST API request/response surfaceNode REST API request/response surfaceStatus: Open.#489 In Twigpine/node;operator: heartbeat loop has no timeout, so a hung chain RPC silently stops all heartbeats
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:mediumDegraded but workaround existsDegraded but workaround existssubsystem:attestationCertificates, anchoring, per-ref attestationCertificates, anchoring, per-ref attestationStatus: Open.#488 In Twigpine/node;storage(tigris): cold acquire buffers the whole archive in RAM with no in-flight dedup
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:storageBlob/object store, Arweave, IPFS, archivesBlob/object store, Arweave, IPFS, archivesStatus: Open.#487 In Twigpine/node;storage: encrypt_and_pin re-seals withheld blobs through unbounded sync reads with no permit or budget
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:mediumDegraded but workaround existsDegraded but workaround existssubsystem:encryptionEncrypted subtrees, recipient blinding, key zeroizationEncrypted subtrees, recipient blinding, key zeroizationsubsystem:storageBlob/object store, Arweave, IPFS, archivesBlob/object store, Arweave, IPFS, archivesStatus: Open.#486 In Twigpine/node;api(stats): every anonymous stats request loads the full repo inventory and all visibility rules
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:apiNode REST API request/response surfaceNode REST API request/response surfaceStatus: Open.#485 In Twigpine/node;api(pulls): PR diff route materializes unbounded diffs anonymously with no cap or admission
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:apiNode REST API request/response surfaceNode REST API request/response surfaceStatus: Open.#484 In Twigpine/node;