freedomofpress / pressfreedomtracker.us

Code for the U.S. Press Freedom Tracker project website
https://pressfreedomtracker.us
GNU Affero General Public License v3.0
18 stars 7 forks source link

Basic internal security review of the US PFT codebase #645

Closed eloquence closed 3 years ago

eloquence commented 6 years ago

As part of the open source release (and also generally as a good internal practice), we should perform a basic internal security review of this codebase against common web application vulnerabilities in the main codebase or its dependencies; @conorsch also suggested doing so. @emkll I would suggest that we allocate some of your time for this.

conorsch commented 4 years ago

We've gone through a similar process already prior to open-sourcing the SDO repo (https://github.com/freedomofpress/securedrop.org/). SInce this repository will become public, we'll be sparse on the details in this ticket itself, but I'll share some documentation with team members about next steps to coordinate the review.

conorsch commented 3 years ago

Update: we've audited the repo history, and cleaned up a few discussion threads that had sensitive info in them. There are still some outstanding tasks prior to pulling the lever, tracked in https://github.com/freedomofpress/tracker/milestone/1

harrislapiroff commented 3 years ago

@conorsch feel free to close this issue if you think the security audit aspects are complete!

conorsch commented 3 years ago

Yes, satisfied with the review we've performed. Thanks, all.