-
-
Notifications
You must be signed in to change notification settings - Fork 3
security review
github-actions[bot] edited this page Oct 3, 2026
·
1 revision
Status: shipped. Review 1 of a yearly cycle.
- Date: 2026-10-03.
- Reviewer: the maintainer (@tcivie), with the automated tools: clippy pedantic, CodeQL, cargo-deny, zizmor, gitleaks, Socket and dependency review. No outside party took part.
- Scope: the no-leak design (the five layers of ADR 0001), the IPC contract and capabilities, the gatekeeper, the JSON stores, and the GitHub workflows.
- Method: read the design and the code, run the spikes, run the automated tools. The case is in Assurance case.
| Finding | Where found | Status |
|---|---|---|
macOS loopback leak. WKWebView does not send requests to 127.0.0.1 through the proxy. An <img>, <iframe>, fetch or WebSocket to a local port went out directly. |
Spike S1 | Fixed by design. The gatekeeper adds a content security policy to every response. An engine-level content rule list blocks the rest before the first load. Both ship with the browser shell PR. |
The wry WebView2 proxy trap. On Windows, wry drops the proxy_url setting when custom browser arguments are set. Custom arguments without a proxy would mean direct connections. |
Browser shell work | Fixed by design. The Windows arguments always carry --proxy-server and the loopback rule. Ships with the browser shell PR. |
Lint exclusion in release.yml. The calls of the reusable workflows carried zizmor: ignore[self-repository] comments. They went against the no-exclusions rule. |
This review | Fixed in #24. The release gates job replaced the reusable-workflow calls. |
| No DNS block on Windows. The firewall rules from spike S10 block every off-box TCP and UDP path from the engine, but not DNS. | Spike S10 | Open. The engine proxy stays the main control. See the roadmap. |
- The managed I2P install and in-network updates (Phase 3). They are not built.
- The OS-level network layer (L6). It is not built.
2027-10-03. Repeat the review sooner if a new network path, a new IPC command or a new dependency with network code is added.
- 2026-10-03 — First security review recorded — #30.
Generated from docs/wiki in the repository. Edit there, not here.