-
Notifications
You must be signed in to change notification settings - Fork 27
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
In-flight query killed by a Postgres restart returns 500, not the retryable 503
kind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:mediumDegraded but workaround existsDegraded but workaround existssubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:storageBlob/object store, Arweave, IPFS, archivesBlob/object store, Arweave, IPFS, archivesStatus: Open.#256 In Gitlawb/node;Signed requests are replayable for ~600s and are not bound to a target host
kind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:identityDID/UCAN, http-sig auth, push authorizationDID/UCAN, http-sig auth, push authorizationStatus: Open.#253 In Gitlawb/node;Ref certificates name a pusher but retain no pusher-authenticated evidence of the transition
crate:coregitlawb-core — identity, certs, encrypt, DID/UCANgitlawb-core — identity, certs, encrypt, DID/UCANcrate:git-remotegit-remote-gitlawb — the git remote helpergit-remote-gitlawb — the git remote helpercrate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:attestationCertificates, anchoring, per-ref attestationCertificates, anchoring, per-ref attestationsubsystem:encryptionEncrypted subtrees, recipient blinding, key zeroizationEncrypted subtrees, recipient blinding, key zeroizationsubsystem:identityDID/UCAN, http-sig auth, push authorizationDID/UCAN, http-sig auth, push authorizationStatus: Open.#252 In Gitlawb/node;Database outage renders as 500 internal_error, not the retryable 503, on /ipfs/pins, /ipfs/{cid} and /arweave/anchors
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-havesubsystem:apiNode REST API request/response surfaceNode REST API request/response surfaceStatus: Open.#251 In Gitlawb/node;Unauthenticated POST /graphql leaks raw sqlx/Postgres error text in query resolver errors (sibling of #226/#106)
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:apiNode REST API request/response surfaceNode REST API request/response surfaceStatus: Open.#250 In Gitlawb/node;Release automation ships a stale Cargo.lock: lock-sync the release PR and build --locked in CI
bugSomething isn't workingSomething isn't workingkind:ciCI, release, or packaging pipelineCI, release, or packaging pipelinesev:mediumDegraded but workaround existsDegraded but workaround existsStatus: Open.#242 In Gitlawb/node;ci(release): unanchored tag validation glob lets a multiline dispatch input inject step outputs
kind:ciCI, release, or packaging pipelineCI, release, or packaging pipelinesev:mediumDegraded but workaround existsDegraded but workaround existsStatus: Open.#239 In Gitlawb/node;ci(release): docker backfill repoints :latest/:X.Y backward, and manifest publishes any digests present
kind:ciCI, release, or packaging pipelineCI, release, or packaging pipelinesev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundStatus: Open.#238 In Gitlawb/node;ci: npm-publish trusted publishing has no environment/branch gate, so workflow_dispatch can publish arbitrary content
kind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundStatus: Open.#234 In Gitlawb/node;Extract the identity-key module and the bounded name-probe loop from lib.rs
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:refactorRestructure, behavior preservedRestructure, behavior preservedsev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-haveStatus: Open.#232 In Gitlawb/node;Pin the identity key directory to 0700 and create marker files 0600
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:identityDID/UCAN, http-sig auth, push authorizationDID/UCAN, http-sig auth, push authorizationStatus: Open.#231 In Gitlawb/node;Parse GITLAWB_ICAPTCHA_INSECURE value so =0/=false disables the loopback relaxation
kind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-havesubsystem:apiNode REST API request/response surfaceNode REST API request/response surfaceStatus: Open.#227 In Gitlawb/node;