-
There are security considerations mildly out of scope of the repository itself (the repository assumes OS is securely installed) but perhaps we could provide additional tools to make things easier for…
-
As proposed by @Kulga [here](https://github.com/flarum/flarum/commit/569e3a3b5ec862ecae93e0e438dd6a7a4c5012ed#commitcomment-21080215), we should probably change our included Apache configuration (and …
-
### Question
Hey I wanted to ask if you Guys could share the best Settings in SimpleX Chat in terms of security and privacy? Because there are many things which I don't understand or have not much kn…
ghost updated
3 weeks ago
-
### Describe the bug
**Context:**
I believe the recommended way to remove the Server header is via `on_response_prepare`. This works well in most but not all cases.
Since the Server header is a sec…
hofst updated
2 months ago
-
I think we can start tracking down the security features we could add to the COCONUT kernel to improve its security:
- [ ] KASLR
- [ ] Read-only GDT and IDT
- [x] SMEP and SMAP (Enabled in #473) …
p4zuu updated
1 month ago
-
Thanks for your great work on the CWA app.
We are a group of researchers from TU Braunschweig. As part of a research project, we have studied wormhole attacks against Corona contact tracing, especi…
-
Hi,
I'am following the tutorial for improving Umbraco (7.13.2) security here https://our.umbraco.com/documentation/Reference/Security/Security-hardening/#rename-your-umbraco-folder and renamed my…
-
**What would you like to be added**
As part of SIG-Security-Docs, we've been discussing the creation of a hardening guide for Kubernetes. We've got an initial document for the guide's creation here…
-
### Description:
When using `actionlint` to check GitHub Actions workflows, I encountered a warning indicating that `github.head_ref` is potentially untrusted when used directly in an inline script…
-
### OpenTofu Version
```shell
Latest
```
### Use Cases
Some organizations have a distrust of upstream tampering of versions. One way to give peace of mind is by pinning versions to upstream…