RISK-WP-0002: findings publish whole; method docs public except escalation
Operator ruled both. Findings publish as the file a reader gets — including RISK-F-0001's record that this register graded it critical while its fix notice sat unread. A summary would be a second document per finding kept in sync by hand, and drift is the failure this repo most distrusts; and a published register containing only other repos' defects reads as an accusation, while one containing its own reads as a record. Method docs public except escalation, which is restricted because it names spend thresholds and describes when the operator personally is interrupted — a map of where attention is scarce, needed by nobody judging a finding. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
7dc8d01a63
commit
f0db7c83ca
10 changed files with 112 additions and 10 deletions
|
|
@ -20,7 +20,13 @@ likelihood: L2
|
|||
fidelity_modifier: false
|
||||
production_rescore: false
|
||||
disclosure: public
|
||||
publication: pending-handover
|
||||
publication: requested
|
||||
publication_id: risk-f-0001-flex-auth-unauthenticated-check
|
||||
publication_path: "findings/flex-auth-unauthenticated-check/v1/index.html"
|
||||
publication_subtitle: "The estate's authorization oracle authenticated no caller for as long as the endpoint existed. Found by reading, not by monitoring; fixed in two days."
|
||||
revision: "graded-1"
|
||||
last_reviewed: "2026-08-20"
|
||||
review_interval: 6m
|
||||
embargo_condition: "met 2026-08-19 — FLEX-WP-0015 finished, live probes return 401"
|
||||
embargo_since: "2026-08-19"
|
||||
embargo_review: "2026-08-19"
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue