docs: add SECURITY.md - #266
Conversation
|
Warning Review limit reached
Next review available in: 57 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Walkthrough
ChangesSecurity Disclosure Guidance
Estimated code review effort: 1 (Trivial) | ~2 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@SECURITY.md`:
- Line 5: Update the security-report acknowledgment statement in SECURITY.md so
Ark publicly thanks or acknowledges reporters only when they provide explicit
consent, avoiding any promise of automatic public recognition.
- Around line 9-18: Update the SECURITY.md PGP key table entries for Marco
Argentieri, Pietralberto Mazza, and Andrew Camilleri to publish each key’s
complete fingerprint instead of truncated values. Replace the placeholder gpg
command with a concrete key URL example and add a separate executable
fingerprint comparison step that verifies the fetched key against the published
fingerprint.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
|
|
||
| Security is a top priority for Ark. If you discover a security issue, please bring it to our attention right away. Please DO NOT file a public issue, instead send your report privately by sending an email to <security@arklabs.to>. | ||
|
|
||
| Security reports are greatly appreciated and we will publicly thank you for it. |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
Make public acknowledgment opt-in.
Line 5 promises public thanks without reporter consent. This can reveal the reporter’s identity or the existence of a report. State that Ark will acknowledge reporters only with explicit consent.
Proposed wording
- Security reports are greatly appreciated and we will publicly thank you for it.
+ Security reports are greatly appreciated. With your explicit consent, we may publicly acknowledge your report.📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| Security reports are greatly appreciated and we will publicly thank you for it. | |
| Security reports are greatly appreciated. With your explicit consent, we may publicly acknowledge your report. |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@SECURITY.md` at line 5, Update the security-report acknowledgment statement
in SECURITY.md so Ark publicly thanks or acknowledges reporters only when they
provide explicit consent, avoiding any promise of automatic public recognition.
| | Name | PGP Public Key URL | Fingerprint | | ||
| |------|-------------|-------------| | ||
| | Marco Argentieri | [https://github.com/tiero.gpg](https://github.com/tiero.gpg) | 0F6586CE8DA12FB1 | | ||
| | Pietralberto Mazza | [https://github.com/altafan.gpg](https://github.com/altafan.gpg) | 6C7639DEA147673B | | ||
| | Andrew Camilleri | [https://github.com/Kukks.gpg](https://github.com/Kukks.gpg) | F918A46E23064E28 | | ||
|
|
||
| You can import a key by running the following command in your terminal and verify the fingerprint matches the one above: | ||
|
|
||
| ```bash | ||
| gpg --fetch-keys <PGP Public Key URL> |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
Publish full fingerprints and an executable verification step.
Lines 11-13 contain only 16 hexadecimal characters. These values are not sufficient as full fingerprint verification targets. Publish the complete fingerprint for each key.
Line 18 also uses <PGP Public Key URL> as a shell placeholder. The command fetches a key but does not verify its fingerprint. Show a concrete URL and a separate fingerprint comparison step.
Proposed documentation change
-| Name | PGP Public Key URL | Fingerprint |
+| Name | PGP Public Key URL | Full Fingerprint |
...
-gpg --fetch-keys <PGP Public Key URL>
+gpg --fetch-keys https://github.com/tiero.gpg
+gpg --fingerprint FULL_FINGERPRINT🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@SECURITY.md` around lines 9 - 18, Update the SECURITY.md PGP key table
entries for Marco Argentieri, Pietralberto Mazza, and Andrew Camilleri to
publish each key’s complete fingerprint instead of truncated values. Replace the
placeholder gpg command with a concrete key URL example and add a separate
executable fingerprint comparison step that verifies the fetched key against the
published fingerprint.
arkana-ai-bot
left a comment
There was a problem hiding this comment.
Arkana Review — docs: add SECURITY.md
Note: This PR is already merged; findings are recorded for the record and to inform follow-up issues.
No protocol-critical paths touched (no VTXO/signing/forfeit/round/exit changes). Two findings below.
FINDING 1 — Truncated PGP key IDs, not full fingerprints [medium]
SECURITY.md:11–13
| Marco Argentieri | … | 0F6586CE8DA12FB1 |
| Pietralberto Mazza | … | 6C7639DEA147673B |
| Andrew Camilleri | … | F918A46E23064E28 |
All three values are 16 hex characters — 64-bit short key IDs, not PGP fingerprints (which are 40 hex characters / 160 bits). Short key IDs have a well-documented collision attack surface: the "Evil32" project (2016) demonstrated it is cheap to generate a keypair sharing any chosen short ID. A reporter following the instructions — gpg --fetch-keys <URL>, then checking the last 16 chars — could be deceived if an attacker pre-positions a colliding key.
Since the URL (github.com/tiero.gpg etc.) is the primary trust anchor here, the practical risk is lower than a pure short-ID scheme, but the document is supposed to be the authoritative verification step. Replace each value with the full 40-character fingerprint, e.g.:
gpg --with-fingerprint <key-file>
# or
gpg --fingerprint <keyid>
Same issue exists verbatim in arkd/SECURITY.md — fix both.
FINDING 2 — Other SDK repos have no SECURITY.md [low]
ts-sdk, go-sdk, and dotnet-sdk have no SECURITY.md. A researcher finding a vulnerability through any of those entry points has no documented disclosure path. Follow-up PRs mirroring this file (with the same full-fingerprint fix) to those repos would close the gap.
Non-findings / confirmed correct
- Intentional removal of the Nostr NIP-04 DM channel (documented in PR body) — no objection.
gpg --fetch-keysinstruction is correct syntax.- Email address
security@arklabs.toconsistent with other Ark repos. - No suspicious-content findings in PR title, body, or diff.
Adds the security disclosure policy, copied from the
arkdrepo, with the nostr DM contact removed — reports go to security@arklabs.to.🤖 Generated with Claude Code
https://claude.ai/code/session_01Ek8iDTwb1V7PVh1kKewSVg
Generated by Claude Code
Summary by CodeRabbit