mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 23:18:24 +00:00
docs(explanation): document disclosure guidance for private services
Teams asking how a private service receives CVE and security reports had no documented answer, inviting ad-hoc workarounds that could weaken the access boundary. Adds a "Disclosure and outside contributions" section to the GRASP-08 design doc: the security contact is discoverable via the public NIP-11 contact field and the NIP-05 root identity; reports arrive as NIP-17 encrypted DMs on the maintainers' public mailbox relays; collaboration access is granted by adding the reporter to NGIT_PRIVATE_MEMBERS; and a non-member submission lane is deliberately not implemented because it would reopen the unauthenticated write surface GRASP-08 exists to close (mirroring the GRASP-06 incompatibility rationale). Doc-only change; no behavior is added or altered. Validated against the discovery surfaces the implementation actually exposes (unauthenticated NIP-11 and NIP-05 in private mode).
This commit is contained in:
@@ -201,6 +201,30 @@ repositories it mirrors. Only relays advertising `GRASP-08` in their NIP-11
|
||||
`supported_grasps` mint derived members; configured `NGIT_PRIVATE_MEMBERS`
|
||||
are unaffected.
|
||||
|
||||
## Disclosure and outside contributions
|
||||
|
||||
Teams running a private service still receive security reports (CVEs,
|
||||
vulnerability disclosures) from people outside the member set. GRASP-08 keeps
|
||||
that path open without weakening the access boundary:
|
||||
|
||||
- **Finding the contact**: the service's existence and operator identity are
|
||||
deliberately public. The security contact is discoverable through the
|
||||
NIP-11 `contact` field and the NIP-05 root identity (`_@domain`), both
|
||||
served unauthenticated.
|
||||
- **Sending a report**: reports arrive as NIP-17 encrypted direct messages on
|
||||
the maintainers' public mailbox relays. Nothing about a private repository
|
||||
needs to be readable for a reporter to reach its maintainers privately.
|
||||
- **Granting collaboration access**: when a report leads to joint work, the
|
||||
operator adds the reporter to `NGIT_PRIVATE_MEMBERS`. Membership grants
|
||||
read access to the whole trust domain (see "Why membership is
|
||||
service-wide"), which is the intended granularity: triaging a
|
||||
vulnerability together means trusting the reporter with the codebase.
|
||||
- **No non-member submission lane**: a dedicated unauthenticated inbox for
|
||||
outside patches or PR events is deliberately not implemented. It would
|
||||
reopen exactly the unauthenticated write surface GRASP-08 exists to close —
|
||||
the same reasoning that makes private mode refuse to combine with
|
||||
GRASP-06.
|
||||
|
||||
## Follow-up scope
|
||||
|
||||
Deliberately excluded from the initial single-service implementation:
|
||||
|
||||
Reference in New Issue
Block a user