From e741d9ddc4bf35160434d8d01fa66a4021c63719 Mon Sep 17 00:00:00 2001 From: DanConwayDev Date: Sat, 15 Aug 2026 14:17:28 +0000 Subject: [PATCH] docs(explanation): document disclosure guidance for private services Teams asking how a private service receives CVE and security reports had no documented answer, inviting ad-hoc workarounds that could weaken the access boundary. Adds a "Disclosure and outside contributions" section to the GRASP-08 design doc: the security contact is discoverable via the public NIP-11 contact field and the NIP-05 root identity; reports arrive as NIP-17 encrypted DMs on the maintainers' public mailbox relays; collaboration access is granted by adding the reporter to NGIT_PRIVATE_MEMBERS; and a non-member submission lane is deliberately not implemented because it would reopen the unauthenticated write surface GRASP-08 exists to close (mirroring the GRASP-06 incompatibility rationale). Doc-only change; no behavior is added or altered. Validated against the discovery surfaces the implementation actually exposes (unauthenticated NIP-11 and NIP-05 in private mode). --- docs/explanation/grasp-08-private-service.md | 24 ++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/docs/explanation/grasp-08-private-service.md b/docs/explanation/grasp-08-private-service.md index 408e29c..6a9dc36 100644 --- a/docs/explanation/grasp-08-private-service.md +++ b/docs/explanation/grasp-08-private-service.md @@ -201,6 +201,30 @@ repositories it mirrors. Only relays advertising `GRASP-08` in their NIP-11 `supported_grasps` mint derived members; configured `NGIT_PRIVATE_MEMBERS` are unaffected. +## Disclosure and outside contributions + +Teams running a private service still receive security reports (CVEs, +vulnerability disclosures) from people outside the member set. GRASP-08 keeps +that path open without weakening the access boundary: + +- **Finding the contact**: the service's existence and operator identity are + deliberately public. The security contact is discoverable through the + NIP-11 `contact` field and the NIP-05 root identity (`_@domain`), both + served unauthenticated. +- **Sending a report**: reports arrive as NIP-17 encrypted direct messages on + the maintainers' public mailbox relays. Nothing about a private repository + needs to be readable for a reporter to reach its maintainers privately. +- **Granting collaboration access**: when a report leads to joint work, the + operator adds the reporter to `NGIT_PRIVATE_MEMBERS`. Membership grants + read access to the whole trust domain (see "Why membership is + service-wide"), which is the intended granularity: triaging a + vulnerability together means trusting the reporter with the codebase. +- **No non-member submission lane**: a dedicated unauthenticated inbox for + outside patches or PR events is deliberately not implemented. It would + reopen exactly the unauthenticated write surface GRASP-08 exists to close — + the same reasoning that makes private mode refuse to combine with + GRASP-06. + ## Follow-up scope Deliberately excluded from the initial single-service implementation: