Skip to content

docs(security): publish the September 2026 security assessment (SEC-2026-09) - #1201

Merged
TaekeK merged 1 commit into
mainfrom
feature/security-assessment-2026-09
Sep 14, 2026
Merged

TaekeK merged 1 commit into
mainfrom
feature/security-assessment-2026-09

Conversation

@WimvandenHeijkant

Copy link
Copy Markdown
Contributor

Summary

Publishes the September 2026 security re-assessment as a docs page, alongside the June 2026 assessment. It covers:

  • Review record: scope, method, all 53 findings by severity, and the remediation pull request for each.
  • Upgrade notes for operators, since several fixes tighten defaults that existing installs may rely on.
  • Regression check against June 2026, and the strengths the review confirmed.

The page is linked in the docs navigation under Quality & audits, and from the June assessment page.

Exploit detail is deliberately left out, matching the June page. The full technical report stays confidential.

Remediation PRs

PR Scope
#1200 Per-system boundary on crawler ingest (C-01, H-04, M-05, M-07, L-16)
#1196 Vault read paths and crawler credential custody (H-01, H-02, M-02, M-06, M-10, L-04, L-05, I-03)
#1198 SSRF guard bypasses and worker-side URL validation (H-03, M-02, M-03, M-12, I-05)
#1193 Read-token guard, admin read gates, query hygiene (M-01, L-01, L-02, L-03, L-12, L-14, L-15, I-08, I-10)
#1199 Request-layer hardening, exporter and CSP fixes (H-07, M-04, M-09, M-13, L-11, L-13, L-17, L-18)
#1194 Build-agent sandboxing, CI permissions, dependencies (H-05, L-19, I-01, I-02)
#1197 Azure credentials and networking, master key isolation, container hardening (H-06, M-08, M-14, L-19, I-04)
#1195 Worker and crawler fail-safes and credential hygiene (M-11, L-06, L-07, L-08, L-09, L-10, I-11)

Notes for the reviewer

  • Status cells: every status reads "Fix in review". Per the maintenance note on both assessment pages, they are flipped in a single reconciliation pass on main after the fix PRs merge, not on branches.
  • June page: the only change to docs/security/assessment.md is a link to the new page. No status rows were touched.
  • Merge order: this PR can merge before or after the fix PRs. The upgrade notes describe behaviour that ships with those PRs.

🤖 Generated with Claude Code

Adds a public, sanitised record of the September 2026 white-box
re-assessment: scope, method, all 53 findings by severity with their
remediation pull requests (#1193-#1200), upgrade notes for operators,
the regression check against June 2026, and confirmed strengths.
Linked from the docs navigation and from the June assessment page.
Exploit detail is left out, matching the June page.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@TaekeK
TaekeK merged commit 890fd67 into main Sep 14, 2026
32 checks passed
@TaekeK
TaekeK deleted the feature/security-assessment-2026-09 branch September 14, 2026 07:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants