chore(security): triage audit roll-up findings (PMS-504) #373
Loading…
Reference in a new issue
No description provided.
Delete branch "chore/PMS-504-security-audit-triage"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Triage all 38 medium/low/info findings from the 2026-06-25 mokosh-server security audit. Adds dev-docs/audits/security-2026-06-25/mokosh-server-triage.md dispositioning every finding as FIXED, RISK-ACCEPTED, FOLLOW-UP (own issue, TBD until a human files it - this automated run cannot create YouTrack issues), or ALREADY-FIXED, mirroring the mokosh-apps MAPPS-308 roll-up format.
Applied the contained, obviously-correct fixes inline; larger architectural, data-migration, infra, and CI-policy items are dispositioned as grouped follow-ups for separate tracked issues.
Fixed in this change:
Risk-accepted: M6 (partial), M15, L1, I1 - rationale in the triage doc.
#PMS-504