Skip to content

docs(security): add 2026-04 tracker demo security review#15

Merged
josecelano merged 12 commits intotorrust:mainfrom
josecelano-bot:13-add-recurring-security-review-plan
Apr 10, 2026
Merged

docs(security): add 2026-04 tracker demo security review#15
josecelano merged 12 commits intotorrust:mainfrom
josecelano-bot:13-add-recurring-security-review-plan

Conversation

@josecelano-bot
Copy link
Copy Markdown
Contributor

Summary

This PR adds the recurring security review plan and the first completed 2026-04 review cycle for the tracker demo.

It includes:

  • the reusable security review process and review-folder structure
  • the seeded 2026-04 review workspace and summary docs
  • documented public-surface and static-config review results
  • clarified linting guidance and supporting dictionary updates
  • issue and review documentation needed to continue future cycles cleanly

Confirmed Findings

The 2026-04 review currently records these low-severity findings:

  • Public Grafana host discloses operational metadata before auth
  • Public HTTPS hosts do not advertise HSTS
  • Mutable container tags reduce deployment traceability
  • Public tracker API host returns 500 with internal auth error text

Validation

  • ./scripts/lint.sh

Notes

The static-config and public-surface review is complete in-repo. Remaining unresolved items are explicitly documented as host-runtime evidence blockers.

Refs: #13

@josecelano josecelano self-assigned this Apr 10, 2026
@josecelano-bot josecelano-bot force-pushed the 13-add-recurring-security-review-plan branch from e009f71 to ef593c5 Compare April 10, 2026 06:53
@josecelano
Copy link
Copy Markdown
Member

ACK ef593c5

@josecelano josecelano merged commit ebd67d7 into torrust:main Apr 10, 2026
1 check passed
@josecelano josecelano linked an issue Apr 10, 2026 that may be closed by this pull request
13 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs: add recurring security review plan

2 participants