-
Notifications
You must be signed in to change notification settings - Fork 27
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
Unsigned announce repoints a peer's http_url and inherits its reachable=true federation gate
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningStatus: Open.#270 In Gitlawb/node;Anonymous /api/v1/peers/{did}/ping has no auth or per-IP brake, and now probes the target's database
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIStatus: Open.#269 In Gitlawb/node;Unauthenticated task reads expose agent-task UCAN tokens, payloads, and private-repo IDs on both GraphQL and REST
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:mediumDegraded but workaround existsDegraded but workaround existssubsystem:apiNode REST API request/response surfaceNode REST API request/response surfaceStatus: Open.#268 In Gitlawb/node;ci(docker): Dockerfile.bins pins rust:1.85 below the 1.91 MSRV, so it cannot build
kind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorkind:ciCI, release, or packaging pipelineCI, release, or packaging pipelinesev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-haveStatus: Open.#266 In Gitlawb/node;ci(docker): the Dockerfile dependency-cache layer is a no-op, every image build is cold
kind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorkind:ciCI, release, or packaging pipelineCI, release, or packaging pipelinesev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-haveStatus: Open.#265 In Gitlawb/node;gitlawb-node-2 and -3 do not set GITLAWB_TRUSTED_PROXY, collapsing four per-IP limiters into one shared bucket
kind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:mediumDegraded but workaround existsDegraded but workaround existssubsystem:apiNode REST API request/response surfaceNode REST API request/response surfaceStatus: Open.#264 In Gitlawb/node;Pre-auth request buffering has no duration bound, so a permissionless caller can exhaust node memory
kind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:mediumDegraded but workaround existsDegraded but workaround existssubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:peersPeer announce, discovery, and registryPeer announce, discovery, and registrysubsystem:replicationMirror, replica, and cross-node syncMirror, replica, and cross-node syncsubsystem:storageBlob/object store, Arweave, IPFS, archivesBlob/object store, Arweave, IPFS, archivesStatus: Open.#263 In Gitlawb/node;gl init's create-repo path loses the status when the error body is not JSON
kind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-havesubsystem:apiNode REST API request/response surfaceNode REST API request/response surfaceStatus: Open.#260 In Gitlawb/node;Signature ledger: nonce-arm identity keying is unpinned, and the ledger-full 429 carries no Retry-After
kind:featureNew capability or surfaceNew capability or surfacesev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-havesubsystem:attestationCertificates, anchoring, per-ref attestationCertificates, anchoring, per-ref attestationsubsystem:identityDID/UCAN, http-sig auth, push authorizationDID/UCAN, http-sig auth, push authorizationStatus: Open.#259 In Gitlawb/node;GITLAWB_REQUIRE_SIGNATURE_NONCE checks nonce length, not uniqueness
kind:docsDocs and comments onlyDocs and comments onlysev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-havesubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:attestationCertificates, anchoring, per-ref attestationCertificates, anchoring, per-ref attestationStatus: Open.#258 In Gitlawb/node;GraphQL mutations are not covered by the spent-signature ledger
kind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:replicationMirror, replica, and cross-node syncMirror, replica, and cross-node syncStatus: Open.#257 In Gitlawb/node;In-flight query killed by a Postgres restart returns 500, not the retryable 503
kind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:mediumDegraded but workaround existsDegraded but workaround existssubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:storageBlob/object store, Arweave, IPFS, archivesBlob/object store, Arweave, IPFS, archivesStatus: Open.#256 In Gitlawb/node;