Commit History

Autor SHA1 Mensaxe Data
  chiappa 9c0fef58d2 fix: enforce list<string> shape in RoleMappingRepository (SEC_REVIEW F51) hai 3 días
  chiappa 1ed9341c2c docs: mark SEC_REVIEW F50 as fixed in 6cc66ef hai 3 días
  chiappa 6cc66ef4ec fix: tight redirect policy + private-host guard on GeoIP client (SEC_REVIEW F50) hai 3 días
  chiappa 8210d3ee58 docs: mark SEC_REVIEW F49 as fixed in 6580a5b hai 3 días
  chiappa 6580a5b3cd fix: stream DB-IP gunzip with size cap (SEC_REVIEW F49) hai 3 días
  chiappa 781c356f38 docs: mark SEC_REVIEW F48 as fixed in c380d12 hai 3 días
  chiappa c380d126e9 fix: enforce uncompressed-size cap on MaxMind tarball extract (SEC_REVIEW F48) hai 3 días
  chiappa 9f79fbf3c8 docs: mark SEC_REVIEW F47 as fixed in f7a727d hai 3 días
  chiappa f7a727da7c fix: charset gate on AuditController *_kind filters (SEC_REVIEW F47) hai 3 días
  chiappa 9af6cce2de docs: mark SEC_REVIEW F46 as fixed by F30 (2cc1924) hai 3 días
  chiappa fc6415ca6f docs: mark SEC_REVIEW F45 as fixed by F25 (33e9198) hai 3 días
  chiappa 82124b9d94 docs: mark SEC_REVIEW F44 as fixed in 1a705f6 hai 3 días
  chiappa 1a705f6b64 fix: validate job name regex before audit emit (SEC_REVIEW F44) hai 3 días
  chiappa bb72a427b4 docs: mark SEC_REVIEW F43 as fixed in 8ff409f hai 3 días
  chiappa 8ff409fff2 fix: tighten /ips/{ip} route pattern to IP charset (SEC_REVIEW F43) hai 3 días
  chiappa 782faf23f3 docs: mark SEC_REVIEW F42 as fixed in cc77749 hai 3 días
  chiappa cc77749fca fix: enforce role allowlist on UI policy proxies (SEC_REVIEW F42) hai 3 días
  chiappa af42ca5fbc docs: mark SEC_REVIEW F41 as fixed in 4ca69f3 hai 3 días
  chiappa 4ca69f30b6 fix: dedicated audit row when reporter/consumer audit_enabled flips (SEC_REVIEW F41) hai 3 días
  chiappa 8ac4af659f docs: mark SEC_REVIEW F40 as fixed in 30c0604 hai 3 días
  chiappa 30c0604e49 fix: rotate CSRF token on session-id regeneration (SEC_REVIEW F40) hai 3 días
  chiappa 35645140e0 docs: mark SEC_REVIEW F39 as fixed in 0c79c1b hai 3 días
  chiappa 0c79c1bb2b fix: assert TokenIssuer base32 input length, remove dead pad (SEC_REVIEW F39) hai 3 días
  chiappa 41564642cf docs: mark SEC_REVIEW F38 as fixed in d37890b hai 3 días
  chiappa d37890b68f fix: rate-limit /login/local even when local admin is disabled (SEC_REVIEW F38) hai 3 días
  chiappa 436e670c5a docs: mark SEC_REVIEW F37 as fixed in f2a81ad hai 3 días
  chiappa f2a81ad611 fix: reject weak local-admin password hash at UI boot (SEC_REVIEW F37) hai 3 días
  chiappa a469e38cb3 docs: mark SEC_REVIEW F36 as fixed in 2c3b65b hai 3 días
  chiappa 2c3b65b469 fix: revalidate UI session against api periodically (SEC_REVIEW F36) hai 3 días
  chiappa 9b09048f24 docs: mark SEC_REVIEW F35 as fixed in d39ab01 hai 3 días