Commit Graph
4 Commits
Author SHA1 Message Date
Frank_zhuandwyuc 9cd8051461 docs: align security and behaviour claims with shipped code (#1592)
ACCESS_CODE unset remains fail-open in middleware, document reads are
capability-by-id via the anonymous owner cookie (not x-learner-key),
and the README action/skill counts match the Action union and
skills/agent-runtime.

Closes #1587

Co-authored-by: wyuc <wang-yc24@mails.tsinghua.edu.cn>
2026-09-20 16:39:12 +08:00
wyucandClaude Opus 5 8e6a4cacaa docs(security): document deployment assumptions and pre-report checks (#1511)
Add a "Before You Report" section (reproduce on the latest release, check
published advisories, prefer the default deployment) and a "Deployment
Assumptions" section describing the boundaries reports are assessed against:
ACCESS_CODE is a shared password, the render service isolates only with its
shipped egress lockdown, forwarding headers are trusted only with
TRUST_PROXY_HEADERS, PERSISTENCE_DEV_TOKEN is not user isolation, and
operator-set endpoints are trusted configuration.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-15 09:37:35 +02:00
wyucandClaude Fable 5.1 7d989490f8 docs(security): state the severity and CVE process for advisories (#1417)
Add a triage section that says how severity is assigned and that
severity objections are answered in the advisory thread before
publication, and a disclosure note that maintainers request the CVE
through GitHub at publication time and keep the published advisory
consistent with the CVE record.


Claude-Session: https://claude.ai/code/session_01GRaNc5E88r41GUWt2Y3uiQ

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-08 19:06:09 +02:00
fai1424andwyuc 787e2d1ce3 Create SECURITY.md (#281)
Co-authored-by: wyuc <wang-yc24@mails.tsinghua.edu.cn>
2026-03-30 20:33:29 +08:00