Messages by Date
-
2026/02/20
Re: [PR] Bump astral-sh/setup-uv from 7.2.0 to 7.3.0 (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [I] Work on using config option for alpha-only (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [I] Improve error reporting when /resolve/tabulated data is unavailable (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [I] Improve error reporting when /resolve/tabulated data is unavailable (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [I] Make test email address conditional on test environment (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [PR] Introduce ATR_STATUS and control recipient lists (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [I] /api/project/releases/{name} should return 404 for non-existent project (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [PR] Return 404 when project is unknown in api endpoint call (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [I] SSH server: Configure explicit cipher suites, KEX, and MAC algorithms (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [I] SSH server: Configure explicit cipher suites, KEX, and MAC algorithms (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [PR] Use the intersection of algorithms from asyncssh and ssh-audit (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [PR] Use the intersection of algorithms from asyncssh and ssh-audit (tooling-trusted-releases)
via GitHub
-
2026/02/20
[GH] Updated implementation of check hash checks for caching (tooling-trusted-releases)
via GitHub
-
2026/02/20
[GH] Updated implementation of check hash checks for caching (tooling-trusted-releases)
via GitHub
-
2026/02/20
[GH] Updated implementation of check hash checks for caching (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [I] Improve the accuracy and UI for the OSV vulnerability scanner (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [I] Require two approvals for important actions (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [I] Fix the form to move files in the finish phase, and add regression tests (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [I] Fix the form to move files in the finish phase, and add regression tests (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [I] Add further validation to check site consistency (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [I] Add further validation to check site consistency (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [PR] #677 - Add explicit ciphers, kex and mac algorithms. (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [PR] #677 - Add explicit ciphers, kex and mac algorithms. (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [PR] Bump flask from 3.1.2 to 3.1.3 (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [PR] Bump werkzeug from 3.1.5 to 3.1.6 (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [PR] Bump werkzeug from 3.1.5 to 3.1.6 (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [PR] Bump flask from 3.1.2 to 3.1.3 (tooling-trusted-releases)
via GitHub
-
2026/02/20
[PR] Bump werkzeug from 3.1.5 to 3.1.6 (tooling-trusted-releases)
via GitHub
-
2026/02/20
[PR] Bump flask from 3.1.2 to 3.1.3 (tooling-trusted-releases)
via GitHub
-
2026/02/20
[I] Fix the form to move files in the finish phase, and add regression tests (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [I] Bug: RAO / maven upload only works for single release artifact (+classifiers) (tooling-trusted-releases)
via GitHub
-
2026/02/20
[PR] Updated implementation of check hash checks for caching (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [I] Bug: RAO / maven upload only works for single release artifact (+classifiers) (tooling-trusted-releases)
via GitHub
-
2026/02/20
Re: [I] Document reproducible builds, signing, SBOMs, and OpenSSF (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Discuss integrations with ECMA standards (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Bug: RAO / maven upload only works for single release artifact (+classifiers) (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Move hardcoded committee membership to external configuration (tooling-trusted-releases)
via GitHub
-
2026/02/19
[PR] Introduce ATR_STATUS and control recipient lists (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Make test email address conditional on test environment (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Incomplete committee validation in project deletion (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Ensure that a project can only be deleted or archived under certain conditions, and that the state is clear (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Incomplete committee validation in project deletion (tooling-trusted-releases)
via GitHub
-
2026/02/19
[PR] Return 404 when project is unknown in api endpoint call (tooling-trusted-releases)
via GitHub
-
2026/02/19
[PR] Invalidate pats manually 598 (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [PR] Invalidate PATs; fixes #598 (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [PR] Invalidate PATs; fixes #598 (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Storage layer accepts arbitrary user IDs for SSH key and PAT creation (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Add explicit SCM path rejection to `_validate_relpath_string` (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [PR] Block SCM directories (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Escape database values before writing to database (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Escape database values before writing to database (tooling-trusted-releases)
via GitHub
-
2026/02/19
[PR] Block SCM directories (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Add explicit SCM path rejection to `_validate_relpath_string` (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Enforce HTTPS-only for SVN PubSub listener URL in `atr/svn/pubsub.py` (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Enforce HTTPS-only for SVN PubSub listener URL in `atr/svn/pubsub.py` (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Extend secret redaction patterns in `/admin/configuration` endpoint (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [PR] Assure debug mode is only set in development (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Add production safety check for ALLOW_TESTS configuration (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [PR] Redact sensitive configurations (tooling-trusted-releases)
via GitHub
-
2026/02/19
[PR] Redact sensitive configurations (tooling-trusted-releases)
via GitHub
-
2026/02/19
[PR] Assure debug mode is only set in development (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Add LDAP account status check to session and JWT validation (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Add integrity verification for Apache RAT JAR (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Error message says "create" instead of "delete" in `release_delete` (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Add integrity verification for Apache RAT JAR (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Pin syft version in Dockerfile (tooling-trusted-releases)
via GitHub
-
2026/02/19
[I] Bug: RAO / maven upload only works for single release artifact (+classifiers) (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Discuss integrations with ECMA standards (tooling-trusted-releases)
via GitHub
-
2026/02/19
Re: [I] Add rate limiting to Trusted Publisher JWT API endpoints (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Handle session isolation for mixed authentication methods (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Invalidate all SSH keys when user account is disabled (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Invalidate authorization cache and session file cache on logout/session termination (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Add LDAP account status check to session and JWT validation (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Document safe usage of `cmarkgfm` (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Add session regeneration on OAuth authentication (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Implement JWT token revocation mechanism (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Implement server-side session store to enable session revocation (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Create security documentation for authentication defense controls (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Work on using config option for alpha-only (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Make test email address conditional on test environment (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Move hardcoded committee membership to external configuration (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Add production safety check for ALLOW_TESTS configuration (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Implement authentication failure logging (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Add rate limiting to Trusted Publisher JWT API endpoints (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] SSH server lacks brute force protection (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Insufficient archive member path validation in check tasks (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Apply `form.to_relpath()` consistently in `draft.py` and `finish.py` POST handlers (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Path traversal in storage layer `delete_file` and `generate_hash_file` (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Path traversal in attestable file path construction (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Add size limits to LICENSE/NOTICE file reads and remote KEYS fetch (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Add size limits to SSH/rsync file uploads (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Enforce MAX_CONTENT_LENGTH and add file upload size limits across all HTTP entry points (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate compliance with ASVS v5.0.0 L1 criteria (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: documentation (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: documentation (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: denial of service (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: denial of service (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: credential integrity (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: credential integrity (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: brute force identification (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: brute force identification (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: basic access (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: basic access (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: credential stealing (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: credential stealing (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: internal access (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: internal access (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: universal spoofing (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: universal spoofing (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: external access (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: external access (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: weak cryptography (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: weak cryptography (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: cross site scripting (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: cross site scripting (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: server side execution (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate ASVS v5.0.0 compliance: server side execution (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Evaluate compliance with ASVS v5.0.0 L1 criteria (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Document the intended transition to JSON outputs by default in the client (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Document the intended transition to JSON outputs by default in the client (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Make client responses json by default (tooling-releases-client)
via GitHub
-
2026/02/18
Re: [I] Add log sealing (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Add further validation to check site consistency (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Add read-only and read-write test projects (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Add read-only and read-write test projects (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Add a mode for admins to browse as themselves with no admin permissions (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Discuss refining permissions for uploading CI builds into ATR (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Discuss refining permissions for uploading CI builds into ATR (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Implement RAO / Maven connectivity (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Implement RAO / Maven connectivity (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Use accurate Content-Type for file downloads instead of generic application/octet-stream (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Fix Content-Type mismatch — plain text error responses served as text/html in asfquart (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Add explicit charset to JSON and text response helpers (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Fix Content-Type mismatch — JSON returned as text/plain in /result/data endpoint (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Populate `version.py` at build time (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Document pip-audit CVE exception/suppression process (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Add a "historical only" flag for outdated keys (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Use explicit allowlist for GitHub OIDC payload fields (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Extend Dependabot configuration to cover pip and Docker ecosystems (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Pin syft version in Dockerfile (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Add integrity verification for Apache RAT JAR (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Prefix and formatting for LLM audit comments (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Implement LDAP attribute allowlist instead of `ALL_ATTRIBUTES` (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Filter sensitive fields from Task objects in API responses (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Extend secret redaction patterns in `/admin/configuration` endpoint (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Remove `token_hash` from PersonalAccessToken API responses (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Clear JWT token and CSRF token from DOM on session end / timeout (ASVS 14.3.1) (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Use continuation passing style for creating new revisions (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Use continuation passing style for creating new revisions (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Document reproducible builds, signing, SBOMs, and OpenSSF (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Add a mode for admins to browse as themselves with no admin permissions (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Discuss integrations with ECMA standards (tooling-trusted-releases)
via GitHub
-
2026/02/18
[I] Remove release from SVN import options (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Discuss integrations with ECMA standards (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Discuss integrations with ECMA standards (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Discuss integrations with ECMA standards (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Discuss integrations with ECMA standards (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Discuss integrations with ECMA standards (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Discuss integrations with ECMA standards (tooling-trusted-releases)
via GitHub
-
2026/02/18
Re: [I] Discuss integrations with ECMA standards (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [PR] clarify ASF distribution vs third party channels (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [PR] clarify ASF distribution vs third party channels (tooling-trusted-releases)
via GitHub
-
2026/02/17
[PR] clarify ASF distribution vs third party channels (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] Discuss integrations with ECMA standards (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] Discuss integrations with ECMA standards (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] Discuss integrations with ECMA standards (tooling-trusted-releases)
via GitHub
-
2026/02/17
[I] Update docs with relpath (tooling-trusted-releases)
via GitHub
-
2026/02/17
[I] Use continuation passing style for creating new revisions (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] Task worker executes with stale authorization (TOCTOU) (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] Task worker executes with stale authorization (TOCTOU) (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] Ensure that tasks themselves are cached as well as task results (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] Replace `assert` with explicit error handling in OAuth callback (a.k.a. document no -O flag usage) (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] Ensure that tasks themselves are cached as well as task results (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] Replace `assert` with explicit error handling in OAuth callback (a.k.a. document no -O flag usage) (tooling-trusted-releases)
via GitHub
-
2026/02/17
[I] Ensure that tasks themselves are cached as well as task results (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [PR] Use the intersection of algorithms from asyncssh and ssh-audit (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] Replace `assert` with explicit error handling in OAuth callback (a.k.a. document no -O flag usage) (tooling-trusted-releases)
via GitHub
-
2026/02/17
[PR] Use the intersection of algorithms from asyncssh and ssh-audit (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] Task worker executes with stale authorization (TOCTOU) (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] Task worker executes with stale authorization (TOCTOU) (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] Mark `unverified_header_and_payload` as internal and add security warnings (tooling-trusted-releases)
via GitHub
-
2026/02/17
[PR] #677 - Add explicit ciphers, kex and mac algorithms. (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] Explicitly reject JWTs containing `jku`, `x5u`, or `jwk` headers (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] User impersonation via email sender bypass in message.py (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] Add `nbf` (not-before) claim to internally issued JWTs (tooling-trusted-releases)
via GitHub
-
2026/02/17
Re: [I] Replace `assert` with explicit error handling in OAuth callback (a.k.a. document no -O flag usage) (tooling-trusted-releases)
via GitHub
-
2026/02/16
[I] Verify all DistributionPlatform template URLs use HTTPS (tooling-trusted-releases)
via GitHub
-
2026/02/16
[I] Add explicit TLS configuration to LDAP connections in `atr/ldap.py` (tooling-trusted-releases)
via GitHub
-
2026/02/16
[I] Add TLS enforcement to download shell script in `atr/static/sh/download-urls.sh` (tooling-trusted-releases)
via GitHub
-
2026/02/16
Re: [I] Enforce HTTPS-only for SVN PubSub listener URL in `atr/svn/pubsub.py` (tooling-trusted-releases)
via GitHub
-
2026/02/16
[I] Enforce HTTPS-only for SVN PubSub listener URL in `atr/svn/pubsub.py` (tooling-trusted-releases)
via GitHub
-
2026/02/16
[I] Configure explicit TLS version constraints for Hypercorn server (tooling-trusted-releases)
via GitHub
-
2026/02/16
[I] Add STARTTLS initiation to SMTP mail relay in `atr/mail.py` (tooling-trusted-releases)
via GitHub
-
2026/02/16
[I] Add explicit SCM path rejection to `_validate_relpath_string` (tooling-trusted-releases)
via GitHub
-
2026/02/16
[I] Document OAuth architecture and ASVS V10.4.x delegation (tooling-trusted-releases)
via GitHub
-
2026/02/16
[I] Replace `assert` with explicit error handling in OAuth callback (a.k.a. document no -O flag usage) (tooling-trusted-releases)
via GitHub
-
2026/02/16
[I] Document approved cryptographic algorithms for the project (tooling-trusted-releases)
via GitHub
-
2026/02/16
[I] TLS: Add explicit cipher suite configuration for defense-in-depth (tooling-trusted-releases)
via GitHub
-
2026/02/16
[I] SSH server: Configure explicit cipher suites, KEX, and MAC algorithms (tooling-trusted-releases)
via GitHub