Complete SSH transport release audit (#118)
Some checks failed
Dependency security audit / rustsec (push) Has been cancelled
Some checks failed
Dependency security audit / rustsec (push) Has been cancelled
This commit is contained in:
@@ -113,6 +113,10 @@ remain native-host smoke checks because CI cannot emulate those OS services.
|
||||
| Background and window lifecycle | Generation counters reject stale asynchronous results. Lock cancels Git/clipboard work and clears OTP, QR, URI, entry, and editor state. Close and quit use the same dirty guard. |
|
||||
| Repository and domain ownership | The executable source audit rejects repository/Git construction, process launch, OTP/QR parsing, filesystem writes, unsafe blocks, and insecure HTTP literals in production desktop modules. HTTPS and SSH endpoint parsing, host trust, authentication, and protocol behavior remain in `crates/storage`; desktop only presents typed state and native confirmation or masked-passphrase prompts. The folder picker may read only a user-selected QR image; all password-store I/O remains in `crates/storage`. |
|
||||
|
||||
`ssh-transport-audit.md` records the complete two-URL transport lifecycle and
|
||||
the dependency, algorithm, target, artifact, and deliberate-limit evidence
|
||||
shared by desktop, TUI, and CLI.
|
||||
|
||||
Run the complete repository gate after the desktop-specific checks:
|
||||
|
||||
```sh
|
||||
|
||||
Reference in New Issue
Block a user