Report vulnerabilities privately

Use GitHub private vulnerability reporting. Do not open a public issue for a security problem.

A request that demonstrates the issue is more useful than a hypothetical description. Valid reports receive acknowledgement, a note when the fix lands and advisory credit unless the reporter prefers otherwise.

Critical boundaries

  • Tenant isolation. Any cross-schema read or write through the application is the highest-severity class of defect.
  • Delivery. Any path that returns bytes without evaluating current rights is in scope even when a signature verifies.
  • Access scoping. Queries, counts, facets and exports must all render the caller’s access predicate.
  • Credentials. API keys, signing secrets, SCIM tokens and share tokens must not be readable back or logged.
  • Audit chain. Database rules refuse update and delete; verification must detect history rewritten outside those rules.
  • Provenance. A tampered file must never be presented as verified.

Audit and evidence

Governance actions append to a hash-chained ledger. The database makes ordinary update and delete impossible; damctl audit verify checks the chain later.

This detects superuser tampering rather than pretending a database superuser can be prevented from dropping the rules that protect the table. Detection is the honest boundary.

Verify one tenant’s audit history shell
damctl audit verify --tenant acme

Content credentials

StateMeaning
validThe manifest verifies and chains to a known root
untrustedThe signature verifies but its signer is not recognised
invalidThe binding fails; possible tampering, so evidence is retained
noneNo credential is present; this makes no claim about origin

Verification runs on every original without configuration. The manifest is stored under a tier-exempt key, so it remains available after the master moves to Deep Archive.

When derivative signing is configured, rendered files carry a manifest chained to the original. The signing certificate must not be self-signed, the private key must be PKCS#8, and the configured algorithm must match it.

Known limits to design around

  • Human login and SSO are not implemented; operators currently use issued API keys.
  • Virus scanning is off until clamd is configured, and files above the scan-size ceiling are accepted unscanned with a warning.
  • Re-scanning existing assets after signature updates is not implemented.
  • Development credentials and fixtures are intentionally obvious and are not production secrets.