#231: residual-risk list #276

Merged
fable-5 merged 2 commits from issue-231-residual-risks into main 2026-07-31 10:56:31 +02:00
Collaborator

Adds docs/vs-nfd/90-restrisiken.md with the nine deliberate residual risks (incl. all AC entries: #212/#216/#232/#198 and I-23/24/25), each with risk / acceptance rationale / compensating control / decider, plus the binding same-PR maintenance rule. Stacked on #275.

Adds docs/vs-nfd/90-restrisiken.md with the nine deliberate residual risks (incl. all AC entries: #212/#216/#232/#198 and I-23/24/25), each with risk / acceptance rationale / compensating control / decider, plus the binding same-PR maintenance rule. Stacked on #275.
fable-5 added 4 commits 2026-07-31 10:01:13 +02:00
#228: security documentation (architecture, data flows, network plan)
Some checks failed
CI / Lint, typecheck, test (pull_request) Successful in 6m26s
CI / Build container images (pull_request) Successful in 13s
CI / Auth e2e pack (pull_request) Successful in 9m27s
CI / Import/export fidelity gate (pull_request) Failing after 13s
1cf0458593
docs/vs-nfd/60-sicherheitsdokumentation.md: component diagram with per-
service purpose and privileges, network plan digit-exact against the
deploy compose (127.0.0.1-only app bindings, internal-only data zone),
data-flow diagrams (auth, realtime editing incl. LISTEN/NOTIFY and the
60s collab token, export via the pinned sidecars, backup incl. the
ADR-0026 allowlist, and every read channel), named trust boundaries
(reverse proxy, plugin sandbox, outbound SMTP/mirror), and the complete
list of content copies — in-database, on-volume and outside the
instance — that the deletion concept in #229 builds on. Mermaid only,
German (assessor audience), with the maintained-in-same-PR rule stated.

Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
#229: operations manual (install, update, backup/restore, deletion, roles)
All checks were successful
CI / Lint, typecheck, test (pull_request) Successful in 6m33s
CI / Build container images (pull_request) Successful in 15s
CI / Auth e2e pack (pull_request) Successful in 9m20s
CI / Import/export fidelity gate (pull_request) Successful in 1m7s
d641c5dc8a
docs/vs-nfd/70-betriebshandbuch.md: installation as run on the real
stages (airgap variant explicitly pending #218-#221 with what already
exists as groundwork), update/rollback incl. the no-down-migrations
caveat, backup/restore with the ADR-0026 target allowlist and the
rehearsed monthly restore drill (evidence: logs on #98), the full
scheduler-job table (cadences verified against code), the deletion-and-
destruction chapter built on the #228 copy list (per content type:
what deletion reaches, what remains, immediate-destruction path,
decommissioning), and role separation incl. the deliberate limits of a
Site Admin and the honest note that Site Admin read-bypass makes the
content/platform split non-absolute app-side. Every procedure carries
its evidence level (erprobt / nicht geprobt / offen) — nothing claimed
above what was actually executed.

Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
#227: hardening guide with the VS-NfD reference configuration
Some checks failed
CI / Lint, typecheck, test (pull_request) Failing after 15s
CI / Auth e2e pack (pull_request) Has been skipped
CI / Import/export fidelity gate (pull_request) Has been skipped
CI / Build container images (pull_request) Has been skipped
0dc9789cb1
docs/vs-nfd/50-haertungsleitfaden.md: one adoptable profile — every
entry with the exact switch name, value, default and the reason, split
into instance settings (registration closed, api/mcp off, feeds off,
plugins off, classification defaults vs_nfd + upload block, svg reject,
minimal extension list) and deploy-level configuration (empty
BACKUP_ALLOWED_TARGETS enforces backup-local-only outside Site-Admin
reach; tightened session hours; SMTP deliberately unconfigured with the
consequence stated honestly). auth.local.enabled is listed as the one
pending row (#216) with its compensation until then; the guide states
the binding updated-in-same-PR rule for every future switch. Includes
an operator verification checklist (four unauthenticated 404 curls +
readyz + admin spot checks). Cross-referenced from the delimitation
statement (file names made concrete) and consumed by the Grundschutz
mapping (#230).

Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
#231: residual-risk list
All checks were successful
CI / Lint, typecheck, test (pull_request) Successful in 6m22s
CI / Build container images (pull_request) Successful in 28s
CI / Auth e2e pack (pull_request) Successful in 9m4s
CI / Import/export fidelity gate (pull_request) Successful in 1m3s
7fe3ffd936
docs/vs-nfd/90-restrisiken.md: nine entries, each with risk, why it is
accepted, compensating control and decider — unmarked attachment
content (#212), local auth not yet switchable incl. the open runtime-
flippability question (#216), deferred plugin hash pinning (#232), the
one-time git-history secret check with its pattern caveat (#198),
digest-mail titles (I-23, revisit M32), page_links slug residue (I-24),
the IndexedDB endpoint copy (I-25), deliberately unscheduled features,
and the Site-Admin read bypass. Binding same-PR maintenance rule
stated; referenced from the delimitation statement and consumed by the
Grundschutz mapping.

Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
fable-5 force-pushed issue-231-residual-risks from 7fe3ffd936 to 87c1c5ee88 2026-07-31 10:35:39 +02:00 Compare
fable-5 merged commit 87c1c5ee88 into main 2026-07-31 10:56:31 +02:00
Sign in to join this conversation.
No description provided.