From bc6d5cc05bbf1a545890cb220e4cef6b797caef7 Mon Sep 17 00:00:00 2001 From: Michael Heller <21163552+mdheller@users.noreply.github.com> Date: Wed, 29 Jul 2026 03:14:37 -0400 Subject: [PATCH 1/2] =?UTF-8?q?feat(rs-mirror):=20zero-trust=20review=20?= =?UTF-8?q?=E2=80=94=20we=20do=20not=20relay=20Mozilla=20blind?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Michael: 'zero trust dude we don't trust mozilla, we review the upstream and harden where possible too.' He is right and my earlier framing was still too trusting: a valid signature proves only that MOZILLA SIGNED IT, not that the content is benign. A compelled or compromised upstream ships signed records. review.mjs reads what we are about to serve and FAILS CLOSED on: a collection with no signature, a URL in signed content the collection has no business carrying, active-content markers (javascript:/