Remediate six confirmed security issues: deployment-only config keys, bounded provider responses, short-lived registration sessions, private init file mode, FedWiki workflow authorization, and switch preview gates. - Add DeploymentOnly config key declaration; refuse runtime overrides for keys that decide where secrets are sent - Create httplimit package; bound all provider response reads at 8 MiB - Set fifteen-minute deadline on /register sessions - Write mc-config.yaml with 0600 permissions - Derive FedWiki workflow IDs from site IDs; re-authorize sites before mutating activities - Apply switch authorization gates to the proration preview
421 B
421 B
Codex Security scan
Run a Codex Security scan of the repository in your working directory: the
security-scan skill, one standard pass, headless. The repository is a
disposable copy; read anything, run anything. Its SECURITY.md is the
inherited security policy. Scanner output for the whole repository is in
/out/tools/ as leads. Finish when the scan directory holds report.md,
then print the report's summary.