Report vulnerabilities privately
Use GitHub private vulnerability reporting. Do not open a public issue for a security problem.
A request that demonstrates the issue is more useful than a hypothetical description. Valid reports receive acknowledgement, a note when the fix lands and advisory credit unless the reporter prefers otherwise.
Critical boundaries
- Tenant isolation. Any cross-schema read or write through the application is the highest-severity class of defect.
- Delivery. Any path that returns bytes without evaluating current rights is in scope even when a signature verifies.
- Access scoping. Queries, counts, facets and exports must all render the caller’s access predicate.
- Credentials. API keys, signing secrets, SCIM tokens and share tokens must not be readable back or logged.
- Audit chain. Database rules refuse update and delete; verification must detect history rewritten outside those rules.
- Provenance. A tampered file must never be presented as verified.
Audit and evidence
Governance actions append to a hash-chained ledger. The database makes ordinary update and delete impossible; damctl audit verify checks the chain later.
This detects superuser tampering rather than pretending a database superuser can be prevented from dropping the rules that protect the table. Detection is the honest boundary.
damctl audit verify --tenant acmeContent credentials
| State | Meaning |
|---|---|
| valid | The manifest verifies and chains to a known root |
| untrusted | The signature verifies but its signer is not recognised |
| invalid | The binding fails; possible tampering, so evidence is retained |
| none | No credential is present; this makes no claim about origin |
Verification runs on every original without configuration. The manifest is stored under a tier-exempt key, so it remains available after the master moves to Deep Archive.
When derivative signing is configured, rendered files carry a manifest chained to the original. The signing certificate must not be self-signed, the private key must be PKCS#8, and the configured algorithm must match it.
Known limits to design around
- Human login and SSO are not implemented; operators currently use issued API keys.
- Virus scanning is off until clamd is configured, and files above the scan-size ceiling are accepted unscanned with a warning.
- Re-scanning existing assets after signature updates is not implemented.
- Development credentials and fixtures are intentionally obvious and are not production secrets.