docs: record APT security hardening baseline
This commit is contained in:
@@ -0,0 +1,18 @@
|
||||
# APT security hardening baseline
|
||||
|
||||
- Canonical source: GitPeji `peji/Alta-Proxy-Tool`
|
||||
- Starting commit: `a80074ac57b7a4517837b5d95754f5e6433df3ac`
|
||||
- Branch: `hardening/security-foundation`
|
||||
- Original review: `/home/peji/.hermes/reports/alta-proxy-tool-full-review-2026-08-19.md`
|
||||
- Implementation plan: `docs/plans/2026-08-19-apt-security-foundation.md`
|
||||
- Starting package version: `1.0.0`
|
||||
- Starting audit: 25 findings (1 critical, 22 high, 2 moderate); production-only audit 3 findings (2 high, 1 moderate)
|
||||
- Starting release state: GitPeji/GitHub split-brain, no application CI, unsafe unsigned updater, no automated tests
|
||||
|
||||
## Guardrails
|
||||
|
||||
- GitPeji only; GitHub remote removed.
|
||||
- Production Tool Hub and existing downloads remain unchanged.
|
||||
- Synthetic sentinel credentials only in tests.
|
||||
- Work remains on the isolated hardening branch until review gates pass.
|
||||
- No feature additions until Critical/Important security closure.
|
||||
Reference in New Issue
Block a user