-
Notifications
You must be signed in to change notification settings - Fork 3
All issues
Issue creation is restricted in this repository
- #153 · rubenhensen opened
on Apr 30, 2026 30
Issues
is:issue state:open
is:issue state:open
Search results
cryptify: split the notification email into attributed and neutral renderings, behind a one-way kill switch
repo:cryptifyTouches the cryptify repoTouches the cryptify reposecuritySecurity-related issue (vulnerability, hardening, or risk)Security-related issue (vulnerability, hardening, or risk)wayfinder:dispatchWayfinder ticket type: no decisions left, carryable by a coding agentWayfinder ticket type: no decisions left, carryable by a coding agentStatus: Open.#365 In encryption4all/postguard;cryptify: mint an upload challenge and verify it at finalize, reducing to a SenderClaim
repo:cryptifyTouches the cryptify repoTouches the cryptify reposecuritySecurity-related issue (vulnerability, hardening, or risk)Security-related issue (vulnerability, hardening, or risk)wayfinder:dispatchWayfinder ticket type: no decisions left, carryable by a coding agentWayfinder ticket type: no decisions left, carryable by a coding agentStatus: Open.#364 In encryption4all/postguard;cryptify: canonicalize the default-tier accounting key, so one identity cannot mint unlimited quota buckets
repo:cryptifyTouches the cryptify repoTouches the cryptify reposecuritySecurity-related issue (vulnerability, hardening, or risk)Security-related issue (vulnerability, hardening, or risk)wayfinder:dispatchWayfinder ticket type: no decisions left, carryable by a coding agentWayfinder ticket type: no decisions left, carryable by a coding agentwayfinder:in-flightDispatched to a coding agent; claim is an agent's, not a human'sDispatched to a coding agent; claim is an agent's, not a human'sStatus: Open.#363 In encryption4all/postguard;pg-core, pg-wasm: a challenge-signature API for proving possession of a signing key
securitySecurity-related issue (vulnerability, hardening, or risk)Security-related issue (vulnerability, hardening, or risk)wayfinder:dispatchWayfinder ticket type: no decisions left, carryable by a coding agentWayfinder ticket type: no decisions left, carryable by a coding agentwayfinder:in-flightDispatched to a coding agent; claim is an agent's, not a human'sDispatched to a coding agent; claim is an agent's, not a human'sStatus: Open.#362 In encryption4all/postguard;inner MIME: stop base64ing attachments inside the encrypted plaintext (the real double-base64)
repo:sdkTouches the sdk repoTouches the sdk repowayfinder:grillingWayfinder ticket: resolved by conversation, one question at a timeWayfinder ticket: resolved by conversation, one question at a timeStatus: Open.#359 In encryption4all/postguard;docs(pg-core, pg-wasm): the pre-decrypt sender identity is claimed, not verified
securitySecurity-related issue (vulnerability, hardening, or risk)Security-related issue (vulnerability, hardening, or risk)wayfinder:taskWayfinder ticket: manual work unblocking a decision, or execution under this mapWayfinder ticket: manual work unblocking a decision, or execution under this mapStatus: Open.#357 In encryption4all/postguard;pg-wasm: skipEncryption's containers are undecryptable through a real PKG, so its "everyone can decrypt" comment is false
bugSomething isn't workingSomething isn't workingStatus: Open.#356 In encryption4all/postguard;fixtures: give the wire-compat sample set a non-canonical sender identity, and make pg-compat assert the sender policy
wayfinder:dispatchWayfinder ticket type: no decisions left, carryable by a coding agentWayfinder ticket type: no decisions left, carryable by a coding agentwayfinder:in-flightDispatched to a coding agent; claim is an agent's, not a human'sDispatched to a coding agent; claim is an agent's, not a human'sStatus: Open.#355 In encryption4all/postguard;no reader row on any registry has a currency check, so the support window goes stale silently
wayfinder:grillingWayfinder ticket: resolved by conversation, one question at a timeWayfinder ticket: resolved by conversation, one question at a timeStatus: Open.#353 In encryption4all/postguard;decide: postguard-e2e's keyshare flow uses test.test.email, which #250's canonicalization registry does not match
wayfinder:grillingWayfinder ticket: resolved by conversation, one question at a timeWayfinder ticket: resolved by conversation, one question at a timeStatus: Open.#349 In encryption4all/postguard;task: publish GHSA and RUSTSEC advisories for the sender-spoofing defect once the fix ships
securitySecurity-related issue (vulnerability, hardening, or risk)Security-related issue (vulnerability, hardening, or risk)wayfinder:taskWayfinder ticket: manual work unblocking a decision, or execution under this mapWayfinder ticket: manual work unblocking a decision, or execution under this mapStatus: Open.#348 In encryption4all/postguard;decide: may an unauthenticated caller learn cryptify's default-tier upload limits?
wayfinder:grillingWayfinder ticket: resolved by conversation, one question at a timeWayfinder ticket: resolved by conversation, one question at a timeStatus: Open.#344 In encryption4all/postguard;