-
Notifications
You must be signed in to change notification settings - Fork 33
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
The main ruleset merge-queues on ALLGREEN but requires no status checks, so there is nothing that has to be green
kind:ciCI, release, or packaging pipelineCI, release, or packaging pipelinesev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-haveStatus: Open.#361 In Gitlawb/node;Registry::verify_all aborts the whole batch on one malformed attestation, and the test that names the DoS rule cannot see it
crate:attestgitlawb-attest — attestation and verificationgitlawb-attest — attestation and verificationkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-havesubsystem:attestationCertificates, anchoring, per-ref attestationCertificates, anchoring, per-ref attestationStatus: Open.#359 In Gitlawb/node;gitlawb-attest's did:key parser is missing the length bound gitlawb-core already added, so base58 decode is unbounded
crate:attestgitlawb-attest — attestation and verificationgitlawb-attest — attestation and verificationkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-havesubsystem:identityDID/UCAN, http-sig auth, push authorizationDID/UCAN, http-sig auth, push authorizationStatus: Open.#360 In Gitlawb/node;check_created wraps on an extreme created timestamp: the freshness gate accepts one crafted value in release, panics in debug
crate:coregitlawb-core — identity, certs, encrypt, DID/UCANgitlawb-core — identity, certs, encrypt, DID/UCANkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-havesubsystem:identityDID/UCAN, http-sig auth, push authorizationDID/UCAN, http-sig auth, push authorizationStatus: Open.#358 In Gitlawb/node;gl doctor exits 0 whether or not checks failed, so the status carries no signal
crate:glgl — the contributor CLIgl — the contributor CLIkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-havesubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:identityDID/UCAN, http-sig auth, push authorizationDID/UCAN, http-sig auth, push authorizationsubsystem:storageBlob/object store, Arweave, IPFS, archivesBlob/object store, Arweave, IPFS, archivesStatus: Open.#357 In Gitlawb/node;GET /repos/{owner}/{repo}/commits ignores branch and limit, so gl repo commits mislabels HEAD's log as the branch you asked for
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:mediumDegraded but workaround existsDegraded but workaround existssubsystem:apiNode REST API request/response surfaceNode REST API request/response surfaceStatus: Open.#356 In Gitlawb/node;gl quickstart reports "Registered successfully / UCAN saved" on a non-JSON 200, and over a stale token from another node
crate:glgl — the contributor CLIgl — the contributor CLIkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-havesubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:identityDID/UCAN, http-sig auth, push authorizationDID/UCAN, http-sig auth, push authorizationStatus: Open.#355 In Gitlawb/node;gl writes secrets world-readable: a create-then-chmod window on private keys, and ucan.json never chmod'd at all
crate:glgl — the contributor CLIgl — the contributor CLIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:mediumDegraded but workaround existsDegraded but workaround existssubsystem:identityDID/UCAN, http-sig auth, push authorizationDID/UCAN, http-sig auth, push authorizationStatus: Open.#354 In Gitlawb/node;gl pr can only address your own repos: eight subcommands hard-code the caller's DID and silently build a broken URL
crate:glgl — the contributor CLIgl — the contributor CLIkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:mediumDegraded but workaround existsDegraded but workaround existssubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:identityDID/UCAN, http-sig auth, push authorizationDID/UCAN, http-sig auth, push authorizationStatus: Open.#353 In Gitlawb/node;DHT DID records carry no authenticity binding, so any peer can overwrite the mapping for any DID
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-havesubsystem:peersPeer announce, discovery, and registryPeer announce, discovery, and registryStatus: Open.#352 In Gitlawb/node;The sync worker fetches into a live repo with no lease or advisory lock, so a peer notify can prune away an acked push
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:mediumDegraded but workaround existsDegraded but workaround existssubsystem:replicationMirror, replica, and cross-node syncMirror, replica, and cross-node syncStatus: Open.#351 In Gitlawb/node;gl panics on a short or multi-byte timestamp from the node: 8 unguarded fixed-width slices across 5 commands
crate:glgl — the contributor CLIgl — the contributor CLIkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-havesubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:attestationCertificates, anchoring, per-ref attestationCertificates, anchoring, per-ref attestationsubsystem:peersPeer announce, discovery, and registryPeer announce, discovery, and registryStatus: Open.#350 In Gitlawb/node;