Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
272 changes: 272 additions & 0 deletions docs/audit/2026-08-26-audit.html
Original file line number Diff line number Diff line change
@@ -0,0 +1,272 @@
<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Audit — checkmydata-ai</title>
<style>
:root{--bg:#fbfaf8;--surface:#fff;--surface-2:#f4f2ee;--ink:#1a1917;
--ink-soft:#5e5b55;--ink-faint:#8b8780;--line:#e2ded6;--line-2:#c9c4b8;
--ok:#0f7a4a;--ok-bg:#e8f5ee;--warn:#8a5a00;--warn-bg:#fdf3e0;
--bad:#a32a24;--bad-bg:#fdeceb;--info:#1f5c8f;--info-bg:#e9f1f8;--accent:#2a4d8f;
--mono:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;
--sans:-apple-system,BlinkMacSystemFont,"Segoe UI",Inter,system-ui,sans-serif}
@media (prefers-color-scheme: dark){:root:not([data-theme="light"]){
--bg:#16171a;--surface:#1d1f23;--surface-2:#23262b;--ink:#eceae6;
--ink-soft:#a8a49c;--ink-faint:#7c7871;--line:#2e3238;--line-2:#40454d;
--ok:#6fd39b;--ok-bg:#17332a;--warn:#e0a94a;--warn-bg:#33290f;
--bad:#f08a84;--bad-bg:#3a1c1a;--info:#8ec2ee;--info-bg:#15293a;--accent:#8fb4ee}}
*{box-sizing:border-box}
body{margin:0;background:var(--bg);color:var(--ink);font:16px/1.62 var(--sans);
padding:0 0 5rem}
.wrap{max-width:58rem;margin:0 auto;padding:0 1.5rem}
header.top{border-bottom:1px solid var(--line);background:var(--surface);
padding:2.4rem 0 1.8rem;margin-bottom:2.2rem}
.kicker{font:600 .72rem/1 var(--mono);letter-spacing:.14em;text-transform:uppercase;
color:var(--ink-faint);margin:0 0 .8rem}
h1{font-size:1.95rem;line-height:1.18;margin:0 0 .6rem;letter-spacing:-.02em;font-weight:640}
.lede{font-size:1.03rem;color:var(--ink-soft);margin:0;max-width:44rem}
h2{font-size:1.28rem;margin:2.8rem 0 .5rem;font-weight:640;padding-bottom:.4rem;
border-bottom:2px solid var(--line-2)}
h3{font-size:1rem;margin:1.6rem 0 .35rem;font-weight:650}
p{margin:.6rem 0}
code{font:.85em/1.45 var(--mono);background:var(--surface-2);padding:.1em .34em;
border-radius:4px;border:1px solid var(--line)}
pre{background:var(--surface-2);border:1px solid var(--line);border-radius:8px;
padding:.8rem 1rem;overflow-x:auto;font:.79rem/1.55 var(--mono);margin:.6rem 0}
pre code{background:none;border:none;padding:0}
.tw{overflow-x:auto;margin:.9rem 0;border:1px solid var(--line);border-radius:8px;
background:var(--surface)}
table{border-collapse:collapse;width:100%;font-size:.86rem}
th,td{padding:.48rem .7rem;text-align:left;border-bottom:1px solid var(--line);
vertical-align:top}
th{background:var(--surface-2);font-weight:650;font-size:.76rem;letter-spacing:.02em;
text-transform:uppercase;color:var(--ink-soft);white-space:nowrap}
tbody tr:last-child td{border-bottom:none}
td.num,th.num{text-align:right;font-family:var(--mono);font-size:.81rem;white-space:nowrap}
td.mono{font-family:var(--mono);font-size:.79rem}
.pill{display:inline-block;font:600 .7rem/1.35 var(--mono);padding:.12rem .45rem;
border-radius:4px;white-space:nowrap}
.p-ok{background:var(--ok-bg);color:var(--ok)}
.p-warn{background:var(--warn-bg);color:var(--warn)}
.p-bad{background:var(--bad-bg);color:var(--bad)}
.p-info{background:var(--info-bg);color:var(--info)}
.p-neutral{background:var(--surface-2);color:var(--ink-faint)}
.stats{display:grid;grid-template-columns:repeat(auto-fit,minmax(8rem,1fr));
gap:.7rem;margin:1.3rem 0}
.stat{background:var(--surface);border:1px solid var(--line);border-radius:8px;
padding:.7rem .85rem}
.stat .v{font:650 1.35rem/1.1 var(--sans);letter-spacing:-.02em;display:block}
.stat .k{font:.69rem/1.3 var(--mono);color:var(--ink-faint);text-transform:uppercase;
letter-spacing:.05em}
.card{border:1px solid var(--line);border-left:3px solid var(--line-2);
background:var(--surface);border-radius:6px;padding:.9rem 1.1rem;margin:1rem 0}
.card.bad{border-left-color:var(--bad)}.card.warn{border-left-color:var(--warn)}
.card.info{border-left-color:var(--info)}.card.ok{border-left-color:var(--ok)}
.card h3{margin-top:0}
.meta{font:.73rem/1.4 var(--mono);color:var(--ink-faint);margin:.3rem 0 .5rem}
.note{font-size:.86rem;color:var(--ink-soft);border-left:2px solid var(--line-2);
padding-left:.8rem;margin:.8rem 0}
footer{margin-top:3.5rem;padding-top:1.3rem;border-top:1px solid var(--line);
font-size:.81rem;color:var(--ink-faint)}
@media (max-width:640px){h1{font-size:1.5rem}}
</style>
</head>
<body>
<header class="top"><div class="wrap">
<p class="kicker">project-audit · 2026-08-26T16:33:49Z · read-only</p>
<h1>checkmydata-ai</h1>
<p class="lede">Every number below was produced by a command this run executed. What could not be measured is listed as such, never omitted and never counted as clean.</p>
</div></header>
<div class="wrap">
<div class="stats">
<div class="stat"><span class="v">29</span><span class="k">findings</span></div>
<div class="stat"><span class="v">7</span><span class="k">probes run</span></div>
<div class="stat"><span class="v">2</span><span class="k">blind</span></div>
<div class="stat"><span class="v">0</span><span class="k">closed since last</span></div>
<div class="stat"><span class="v">0</span><span class="k">new</span></div>
<div class="stat"><span class="v">0</span><span class="k">open 3+ runs</span></div>
</div>
<p class="note"><strong>First run.</strong> There is no earlier sidecar in this directory, so nothing is reported as closed or new — a diff against a run that never happened would be a claim about nothing. The next audit will have both columns.</p>
<h2>What this project is</h2>
<div class="tw"><table><tbody>
<tr><th>version</th><td>— (no manifest version)</td></tr>
<tr><th>languages</th><td>—</td></tr>
<tr><th>package managers</th><td>—</td></tr>
<tr><th>monorepo</th><td>yes</td></tr>
<tr><th>submodules</th><td>0</td></tr>
<tr><th>CI</th><td>github-actions</td></tr>
<tr><th>deploy targets</th><td>compose, procfile</td></tr>
<tr><th>error telemetry</th><td>none found in manifests</td></tr>
<tr><th>tracked files</th><td>1500</td></tr>
</tbody></table></div>
<h2>Findings</h2>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">backend/tests/integration/test_analytics_collect_e2e.py:126 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">backend/tests/integration/test_analytics_connection_security.py:49 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">backend/tests/integration/test_analytics_connections_api.py:48 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">backend/tests/integration/test_security_rbac.py:302 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">backend/tests/integration/test_vendor_credentials_api.py:31 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">backend/tests/integration/test_vendor_credentials_api.py:185 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">backend/tests/unit/analytics/test_ga4_adapter.py:933 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">backend/tests/unit/services/test_vendor_credential_no_secret_logging.py:36 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">backend/tests/unit/services/test_vendor_credential_service.py:39 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">backend/tests/unit/services/test_vendor_credential_service.py:139 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">backend/tests/unit/services/test_vendor_credential_service.py:161 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">backend/tests/unit/test_connection_config_secrecy.py:19 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">backend/tests/unit/test_connection_lifecycle.py:90 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">backend/tests/unit/test_ssh_key_routes.py:60 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">backend/tests/unit/test_ssh_tunnel.py:326 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">frontend/src/__tests__/components/GA4ConnectionForm.test.tsx:288 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">frontend/src/__tests__/components/VendorCredentialsPanel.test.tsx:122 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">frontend/src/components/ssh/SshKeyManager.tsx:109 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">frontend/src/components/ssh/SshKeyManager.tsx:258 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block is committed in the tree</h3>
<p class="meta">frontend/src/lib/api/vendor-credentials.ts:52 · P=3.0 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer, then remove it from the tree; if it is in history, rotation is the fix and rewriting history is not</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block appears in git history</h3>
<p class="meta">commit c273fa761381 · P=1.5 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block appears in git history</h3>
<p class="meta">commit 5acb82d1fd17 · P=1.5 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block appears in git history</h3>
<p class="meta">commit d6388423fb55 · P=1.5 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block appears in git history</h3>
<p class="meta">commit 4fac5a7d44ad · P=1.5 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block appears in git history</h3>
<p class="meta">commit 3e34591e9045 · P=1.5 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block appears in git history</h3>
<p class="meta">commit d3f7dc9cd8c0 · P=1.5 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block appears in git history</h3>
<p class="meta">commit c9c40974bea5 · P=1.5 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer</p>
</div>
<div class="card bad">
<h3><span class="pill p-bad">critical</span> A private key block appears in git history</h3>
<p class="meta">commit fbf811253b42 · P=1.5 · first seen 2026-08-26</p>
<p><strong>Remedy.</strong> rotate the credential at its issuer</p>
</div>
<div class="card warn">
<h3><span class="pill p-warn">medium</span> A deployed surface reports no errors anywhere its maintainer can see</h3>
<p class="meta">manifests · P=1.0 · first seen 2026-08-26</p>
<p>Deploy targets declared (compose, procfile) with no telemetry dependency in any manifest. A failure on a user&#x27;s machine is invisible.</p>
<pre><code>languages= deploy=compose,procfile telemetry=[]</code></pre>
<p><strong>Remedy.</strong> add an error reporter, or record the decision not to — the gap worth closing is that nobody wrote down which it is</p>
</div>
<h2>What was not looked at</h2>
<p>A probe that could not run returns <code>blind</code>, never <code>clean</code>. An empty section here would mean every probe answered — not that nothing is wrong.</p>
<div class="tw"><table><thead><tr><th>Probe</th><th>Phase</th><th>Why not</th></tr></thead><tbody>
<tr><td class="mono">channel-divergence</td><td>prod</td><td>no version in a manifest to make a claim about</td></tr>
<tr><td class="mono">published-version</td><td>prod</td><td>no name+version in a manifest</td></tr>
</tbody></table></div>
<h2>Probes</h2>
<div class="tw"><table><thead><tr><th>Probe</th><th>Phase</th><th>Verdict</th><th>Note</th></tr></thead><tbody>
<tr><td class="mono">secrets-tree</td><td>probe</td><td><span class="pill p-bad">finding</span></td><td>20 credential pattern(s)</td></tr>
<tr><td class="mono">secrets-history</td><td>probe</td><td><span class="pill p-bad">finding</span></td><td>8 in history</td></tr>
<tr><td class="mono">worktree</td><td>probe</td><td><span class="pill p-ok">clean</span></td><td>working tree clean</td></tr>
<tr><td class="mono">telemetry</td><td>prod</td><td><span class="pill p-bad">finding</span></td><td>no error reporting found</td></tr>
<tr><td class="mono">ci-present</td><td>prod</td><td><span class="pill p-ok">clean</span></td><td>CI configured: github-actions</td></tr>
<tr><td class="mono">docs-present</td><td>seams</td><td><span class="pill p-ok">clean</span></td><td>7 documentation marker(s): README.md, docs, CLAUDE.md, CONTRIBUTING.md, CHANGELOG.md, docs/adr, ARCHITECTURE.md</td></tr>
<tr><td class="mono">gitignore-secrets</td><td>probe</td><td><span class="pill p-ok">clean</span></td><td>no credential-shaped file is tracked</td></tr>
<tr><td class="mono">channel-divergence</td><td>prod</td><td><span class="pill p-neutral">blind</span></td><td>no version in a manifest to make a claim about</td></tr>
<tr><td class="mono">published-version</td><td>prod</td><td><span class="pill p-neutral">blind</span></td><td>no name+version in a manifest</td></tr>
</tbody></table></div>
<footer><p>Generated by <code>project-audit</code> at 2026-08-26T16:33:49Z against <code>/Users/sshlg/DATA/checkmydata-ai</code>. Read-only: this run changed nothing but the two files it wrote. Sidecar: <code>/Users/sshlg/DATA/checkmydata-ai/docs/audit/2026-08-26-audit.json</code>.</p></footer>
</div>
</body>
</html>
Loading
Loading