chiappa
|
221818fd52
docs: mark SEC_REVIEW F74 as fixed in 3235d35
|
3 dní pred |
chiappa
|
3235d35651
fix: cap per-failure warning logs to first attempt per bucket (SEC_REVIEW F74)
|
3 dní pred |
chiappa
|
02916b357e
docs: mark SEC_REVIEW F73 as fixed in 458a224
|
3 dní pred |
chiappa
|
458a224a88
fix: require int getCode() before using as HTTP status (SEC_REVIEW F73)
|
3 dní pred |
chiappa
|
1bb36fe03b
docs: mark SEC_REVIEW F72 as fixed in dd4f688
|
3 dní pred |
chiappa
|
dd4f688f77
fix: cap /ips/{ip} path length at 80 chars (SEC_REVIEW F72)
|
3 dní pred |
chiappa
|
44e41e3e14
docs: mark SEC_REVIEW F71 as fixed in 1bcf7f3
|
3 dní pred |
chiappa
|
1bcf7f312c
fix: bound BlocklistCache with a 16-policy LRU (SEC_REVIEW F71)
|
3 dní pred |
chiappa
|
b7e05ca28b
docs: mark SEC_REVIEW F70 as fixed in 551cb90
|
3 dní pred |
chiappa
|
551cb90a30
fix: cache rendered blocklist body+etag per format (SEC_REVIEW F70)
|
3 dní pred |
chiappa
|
5d3f05045f
docs: mark SEC_REVIEW F69 as fixed in de84fd9
|
3 dní pred |
chiappa
|
de84fd9b1d
fix: cap request body size before BodyParsingMiddleware reads it (SEC_REVIEW F69)
|
3 dní pred |
chiappa
|
df37f60943
docs: mark SEC_REVIEW F68 as fixed in df1a298
|
3 dní pred |
chiappa
|
df1a298c82
fix: gate /api/docs and openapi.yaml behind API_DOCS_PUBLIC (SEC_REVIEW F68)
|
3 dní pred |
chiappa
|
0345b90174
docs: mark SEC_REVIEW F66 and F67 as fixed in 4a764f5
|
3 dní pred |
chiappa
|
4a764f58f0
fix: remove unused APP_SECRET / UI_SECRET (SEC_REVIEW F66 + F67)
|
3 dní pred |
chiappa
|
5c2ecf7fd6
docs: mark SEC_REVIEW F65 as fixed in c439ce1
|
3 dní pred |
chiappa
|
c439ce1db3
fix: scrub raw JWTs and short Bearers in log output (SEC_REVIEW F65)
|
3 dní pred |
chiappa
|
a37e769d2c
docs: mark SEC_REVIEW F64 as fixed by F22
|
3 dní pred |
chiappa
|
637a7b92eb
docs: mark SEC_REVIEW F63 as fixed in d225bfe
|
3 dní pred |
chiappa
|
d225bfe6b9
fix: pin Twig autoescape strategy to 'html' (SEC_REVIEW F63)
|
3 dní pred |
chiappa
|
25f10f0d01
docs: mark SEC_REVIEW F62 as fixed in f044dbb
|
3 dní pred |
chiappa
|
f044dbb6bc
fix: drop style-src 'unsafe-inline' (SEC_REVIEW F62)
|
3 dní pred |
chiappa
|
75e6df3060
docs: mark SEC_REVIEW F61 as fixed in 3556cd1
|
3 dní pred |
chiappa
|
3556cd1920
fix: extend Permissions-Policy deny-list to full hardening (SEC_REVIEW F61)
|
3 dní pred |
chiappa
|
6ff3720983
docs: mark SEC_REVIEW F60 as fixed in 68121fe
|
3 dní pred |
chiappa
|
68121febe2
fix: make HSTS header operator-tuneable for preload opt-in (SEC_REVIEW F60)
|
3 dní pred |
chiappa
|
a1356f9eb2
docs: mark SEC_REVIEW F59 as fixed in 206db1e
|
3 dní pred |
chiappa
|
206db1e492
fix: add COOP / CORP / Cross-Domain-Policies headers (SEC_REVIEW F59)
|
3 dní pred |
chiappa
|
b2d81caa70
docs: mark SEC_REVIEW F58 as fixed in 95e206c
|
3 dní pred |