Close RISK-F-0010 on RPF-WP-0029 evidence (RISK-RULING-2026-09-22-A)

Source default removed, governed upload and restore have receipts, and the
predecessor share is invalidated by owner attestation (no probe, by design).
Fixed, embargo lifted, publication handover pending. Age-key taint referred
to railiance-platform as a possible separate finding.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 6903@bnt-lap001
Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
This commit is contained in:
tegwick 2026-09-22 08:01:39 +02:00
parent 93e142f2b5
commit 81e31b379c
4 changed files with 77 additions and 34 deletions

View file

@ -2,7 +2,7 @@
id: RISK-F-0010
type: finding
title: "Forgejo backup source embeds a WebDAV credential default"
status: open
status: fixed
owner: risk-nexus
reported_by: railiance-platform
reported_via: railiance-platform
@ -12,7 +12,7 @@ date_filed: "2026-08-23"
system: railiance-platform
environment: production
fix_owner: railiance-platform
fix_tracking: RPF-WP-0029-T02
fix_tracking: RPF-WP-0029-T02 (done 2026-09-15)
closure_condition: "provider invalidation plus governed ciphertext upload and restore receipts; source fallback removal alone does not lift the embargo"
verification: RISK-V-0003
# Graded by risk-nexus 2026-09-01 — docs/rulings/2026-09-01-inbox-sweep.md
@ -22,25 +22,24 @@ impact: I2
likelihood: L2
fidelity_modifier: false
production_rescore: false
disclosure: embargoed
embargo_condition: "the provider credential is revoked or invalidated and the literal source default is removed"
embargo_since: "2026-09-01"
embargo_review: "2026-09-15"
disclosure: public
publication: pending-handover
publication_id: risk-f-0010-embedded-backup-webdav-credential
publication_path: "findings/embedded-backup-webdav-credential/v1/index.html"
publication_subtitle: "A backup script carried a literal file-drop credential default; the default is gone, the share is invalidated, and governed upload and restore are proven."
revision: "fixed-1"
embargo_was_condition: "the provider credential is revoked or invalidated and the literal source default is removed"
embargo_lifted: "2026-09-22 — literal default removed (observed) and predecessor share invalidated (owner attestation, no probe by design)"
embargo_was_since: "2026-09-01"
date_fixed: "2026-09-15"
escalation: none
last_checked: "2026-09-05T00:05:51Z"
next_check: "2026-09-05T00:05:51Z"
cadence: instant
clean_streak: 0
waiting_on:
- who: railiance-platform
what: "complete RPF-WP-0029-T02: revoke or invalidate the provider credential and demonstrate governed ciphertext upload plus restore; source fallback removal is established"
since: "2026-09-01"
would_change: "the finding becomes fixed and the embargo lifts"
default: "the low grade and embargo stand; absent provider invalidation and recovery evidence is recorded as a stalled remediation"
default_at: "2026-09-15"
last_checked: "2026-09-22T06:01:01Z"
next_check: "2026-09-22T07:01:01Z"
cadence: 1h
clean_streak: 1
graded_by: risk-nexus
ruling: RISK-RULING-2026-09-01-A
checked_by: "codex/risk-nexus"
ruling: RISK-RULING-2026-09-22-A
checked_by: "worsch"
---
# RISK-F-0010 — Forgejo backup source embeds a WebDAV credential default
@ -133,8 +132,19 @@ predecessor. Open, low, embargoed and no escalation remain appropriate on the
available evidence. The 2026-09-15 review/default is unchanged. The historical
source-default statements above describe the earlier assessments.
## Closure ruling — 2026-09-22
Fixed; embargo lifted; no escalation. All four closure legs are evidenced: the
source default is removed, governed ciphertext upload and restore have receipts
(2026-09-06), and the predecessor share was invalidated on 2026-09-15. The
invalidation rests on owner attestation because probing it would mean
reconstructing the credential. Age-key taint is outside this finding and has
been referred to railiance-platform. Reasoning:
`docs/rulings/2026-09-22-f0010-closure.md`.
## Reviews
- **2026-09-01** — graded from the filed report and a redacted current-source check. The literal default remains; no fix record was found. Cadence starts at instant.
- **2026-09-02** — clean check: literal source default remains; no fix tracking; embargo and 2026-09-15 wait unchanged. Cadence instant → 1h (1 clean in a row); next check 2026-09-02 09:11Z.
- **2026-09-05** — not clean: Confirmed source fallback removal and RPF-WP-0029 tracking; provider invalidation and encrypted upload/restore receipts remain pending. Low grade and embargo retained; see RISK-V-0003. Cadence 1h → instant; checked again immediately.
- **2026-09-22** — clean check: Closed under RISK-RULING-2026-09-22-A: source default absent, upload/restore receipts, predecessor share invalidated by owner attestation; embargo lifted. Cadence instant → 1h (1 clean in a row); next check 2026-09-22 07:01Z.