YunoHost / issues

General issue tracker for the YunoHost project
72 stars 8 forks source link

Install and configure security tools related to a standard use of ynh #1416

Open ketsapiwiq opened 5 years ago

ketsapiwiq commented 5 years ago

We should improve the security model of YunoHost with lightweight and fine-tuned tools for the threat model of a standard YunoHost install (vulnerable web-apps, non-targeted attacks by bots…).

Leads:

Psycojoker commented 5 years ago

A good part of this will be easy to integrate once the diagnosis system will be in place.

At the time where I wanted to handle scheduled configurable automatic updates for YunoHost I've explored the CVE for debian packages and there is actually a json file on debian website that contains all the needed data (don't have the link right now).

I haven't done it yet because we lack a notification system to inform the user that some stuff has happening on their server.