Second blind black-box pentest, this time against v0.2.1 (all round-1 fixes merged: #63 delete auth, #58 burn race atomic claim, #65 listing leak, #66 admin ratelimit, #59/#76 security headers, #74/#78 validation).
Same rules as #61: no source access, no knowledge of prior findings beyond what an external attacker could learn, live HTTP surface only, capped request volume (~2-3k), live-verify every finding with repro, file findings as issues.
Second blind black-box pentest, this time against v0.2.1 (all round-1 fixes merged: #63 delete auth, #58 burn race atomic claim, #65 listing leak, #66 admin ratelimit, #59/#76 security headers, #74/#78 validation).
Same rules as #61: no source access, no knowledge of prior findings beyond what an external attacker could learn, live HTTP surface only, capped request volume (~2-3k), live-verify every finding with repro, file findings as issues.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Second blind black-box pentest, this time against v0.2.1 (all round-1 fixes merged: #63 delete auth, #58 burn race atomic claim, #65 listing leak, #66 admin ratelimit, #59/#76 security headers, #74/#78 validation).
Same rules as #61: no source access, no knowledge of prior findings beyond what an external attacker could learn, live HTTP surface only, capped request volume (~2-3k), live-verify every finding with repro, file findings as issues.