Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
6.6 KiB
Register
Generated by tools/register_index.py from findings/. Do not edit by hand. Last built 2026-09-01.
8 live of 10 findings; 3 notes below the floor.
Findings
| ID | Finding | System | Severity | Disclosure | Escalation | Fix owner | Status | Cadence | Next check |
|---|---|---|---|---|---|---|---|---|---|
| RISK-F-0010 | Forgejo backup source embeds a WebDAV credential default | railiance-platform | unset | unset | unset | railiance-platform | open | instant (0) | — |
| RISK-F-0009 | agent-high-risk-boundary denies 6 of 17 high-risk lanes; the direct bao path is unprotected for the rest | railiance-platform | high | embargoed | none | railiance-platform | open | instant (0) | due |
| RISK-F-0008 | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | answered (t2, answered) | risk-nexus | accepted | instant (0) | due |
| RISK-F-0007 | No consumer's tenant boundary is verified anywhere | estate | high | embargoed | answered (t4, assigned) | per-consumer, on request | accepted | 1h (1) | due |
| RISK-F-0006 | apps-pg has no backup configured at all: R0 means no recovery | railiance-platform | high | public | answered (t3, answered) | railiance-platform | fixed | instant (0) | due |
| RISK-F-0005 | audit-core read path applies no tenant filter; the bound is deployment, not code | audit-core | medium | public | none | audit-core | mitigated | instant (0) | due |
| RISK-F-0004 | tenant-engine events() returns the entire event log unfiltered | tenant-engine | medium | embargoed | none | tenant-engine | open | instant (0) | due |
| RISK-F-0003 | ops-warden agent read-boundary does not fire on ungraded catalog lanes | ops-warden | medium | embargoed | none | ops-warden | mitigated | 8h (2) | due |
| RISK-F-0002 | ops-warden signs SSH certificates with no authorization decision, and its unblock is now unsafe | ops-warden | medium | embargoed | withdrawn (t6, withdrawn-hazard-window-closed) | ops-warden | open | instant (0) | due |
| RISK-F-0001 | flex-auth /v1/check authenticates no caller | flex-auth | high | public | withdrawn (t1, withdrawn-before-sending) | flex-auth | fixed | instant (0) | due |
Constraints
Hazards created by acting in the wrong order. Each binds another finding's remediation.
| From | Binds | Severity | Constraint |
|---|---|---|---|
| RISK-F-0002 | RISK-F-0001 | lifted | LIFTED 2026-08-19 — flex-auth /v1/check now authenticates callers (RISK-F-0001 fixed). Enabling policy.enabled is now an availability question for ops-warden, no longer an attestation hazard. |
Waiting on someone
Every wait resolves on its default date whether or not anyone answers.
Silence never buys a softer grade — see docs/method/dependencies.md.
| Finding | Who | What would change | Default if silent | On |
|---|---|---|---|---|
| RISK-F-0009 | railiance-platform | embargo lifts on coverage; live verification would refine the grade but is not required for it | the eight uncovered paths stand as recorded and the finding is re-raised | 2026-09-03 |
| RISK-F-0008 | audit-core | a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only | encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable | 2026-11-17 |
| RISK-F-0007 | user-engine | likelihood falls for user-engine if a verification exists; a defect becomes its own finding if not | the on-request path is recorded as having produced no answer, which makes the acceptance itself unsupported and is escalated | 2026-09-03 |
| RISK-F-0005 | audit-core | likelihood rises to L3 if any other production credential carries may_read | graded on the sender alone, as stated; the wider question is recorded as unanswered | 2026-09-19 |
Embargoes
Held from publication with a stated condition. A hold with no moving condition is a stall.
| Finding | Since | Lifts when | Re-decided |
|---|---|---|---|
| RISK-F-0009 | 2026-08-20 | railiance-platform reports the deny set covers every high-risk lane with a KV path (live verification refines the grade, it is not the condition) | — |
| RISK-F-0007 | 2026-08-19 | a verification exists for at least one consumer boundary | 2026-09-18 |
| RISK-F-0004 | 2026-08-19 | the read path filters by tenant in code | 2026-09-18 |
| RISK-F-0003 | 2026-08-19 | RISK-F-0009 resolved — the OpenBao deny set covers every high-risk lane with a KV path | 2026-09-18 |
| RISK-F-0002 | 2026-08-19 | FLEX-WP-0015-T02 shipped and ops-warden policy.enabled true in production | 2026-11-17 |
Notes (below the floor)
Seen, deliberately not findings. Not graded, not reviewed, not published.
| ID | Note | Why below the floor |
|---|---|---|
| RISK-N-0004 | No facility answers which zone a workload is in, or what applies there | missing capability, not a defect — there is nothing to route to a fix owner, and the register does not file undone work |
| RISK-N-0003 | Every defect in this register was found by reading, none by monitoring | no owner and no defect — it is an argument about where to invest detection, and the register cannot route an argument |
| RISK-N-0001 | Noisy-neighbour behaviour is uncharacterised | no decision changes today — no tenant shares a saturating workload, and what is missing is measurement work, not a defect to route |
How to read this
Severity is docs/method/severity.md; disclosure docs/method/disclosure.md;
escalation docs/method/escalation.md; the check cadence docs/method/review.md.
Cadence is the ladder rung and the count of consecutive clean checks — a finding at 1q (9)
has held still for a long time; one at instant (0) moved recently. Anything wrong resets it.
A constraint may be graded higher than the finding that carries it — read both.