feat: Document completed tasks for KMS, Cryptography, and Plugin Libraries
- Added detailed task completion records for KMS interface implementation and CLI support for file-based keys. - Documented security enhancements including Argon2id password hashing, audit event contracts, and rate limiting configurations. - Included scoped service support and integration updates for the Plugin platform, ensuring proper DI handling and testing coverage.
This commit is contained in:
@@ -21,7 +21,7 @@ Pre‑GA lines receive **critical** and **high**‑severity fixes only.
|
||||
|
||||
| Channel | PGP‑encrypted? | Target SLA |
|
||||
|---------|---------------|-----------|
|
||||
| `security@stella-ops.org` | **Yes** – PGP key: [`/keys/#pgp`](../keys/#pgp) | 72 h acknowledgement |
|
||||
| `security@stella-ops.org` | **Yes** – PGP key: [`/keys/#pgp`](https://stella-ops.org/keys/#pgp) | 72 h acknowledgement |
|
||||
| Matrix DM → `@sec‑bot:libera.chat` | Optional | 72 h acknowledgement |
|
||||
| Public issue with label `security` | No (for non‑confidential flaws) | 7 d acknowledgement |
|
||||
|
||||
@@ -65,8 +65,8 @@ We aim for **30 days** from report to release for critical/high issues; medium
|
||||
|
||||
| Purpose | Fingerprint | Where to fetch |
|
||||
|---------|-------------|----------------|
|
||||
| **PGP (sec‑team)** | `3A5C 71F3 ... 7D9B` | [`/keys/#pgp`](../keys/#pgp) |
|
||||
| **Cosign release key** | `AB12 ... EF90` | [`/keys/#cosign`](../keys/#cosign) |
|
||||
| **PGP (sec‑team)** | `3A5C 71F3 ... 7D9B` | [`/keys/#pgp`](https://stella-ops.org/keys/#pgp) |
|
||||
| **Cosign release key** | `AB12 ... EF90` | [`/keys/#cosign`](https://stella-ops.org/keys/#cosign) |
|
||||
|
||||
Verify all downloads (TLS 1.3 by default; 1.2 allowed only via a custom TLS provider such as GOST):
|
||||
|
||||
|
||||
Reference in New Issue
Block a user