Skip to content

Security: notthecloudy/astra

Security

SECURITY.md

Security Policy — Astra

  • Version: 0.0.1 (platform/shared/src/version.ts:1 single source)
  • Supported: 0.0.1 (Production Release v0.0.1 — deepwork .slim/deepwork/production-release-v0.0.1.md Phase 4)

1. Supported versions

Version Supported
0.0.1 ✅ (current — package.json:3 / tauri.conf.json:4 / Cargo.toml:3 unified via ASTRA_VERSION)
< 0.0.1 ❌ (pre-release — upgrade to 0.0.1)

2. Reporting a vulnerability

Do not open a public issue for a security report.

  1. Email the maintainers privately (or open a private security advisory on GitHub) with: affected commit (git rev-parse HEAD), repro steps, impact, and whether BackendsInfo (runtime/daemon/src/views.ts:12 security.store 3-state) surfaces it.
  2. We will acknowledge within 3 business days and share a fix timeline.
  3. Please allow us to ship a fix before public disclosure; we will credit you unless you prefer anonymity.

Scrub secrets from repros — SecretGuard (runtime/daemon/src/local-api.ts:1) never logs keys, and health security.store reports only REAL/MOCK/UNAVAILABLE, never key material.

3. Security posture (what is enforced)

  • Loopback-only daemon — runtime/daemon/src/local-api.ts:1 + runtime/daemon/src/boot.ts:65 bind 127.0.0.1:0 (H3+crossws analog, DataPlaneGate 16 → 503 backpressure-dropped at views.ts:78 droppedDataRequests); no remote ASTRA_DAEMON_HOST without auth (deferred per ADR-0015-auth-parity.md — local-first vault vs AIRI OIDC).
  • RuntimePaths jail — platform/shared/src/runtime-paths.ts:1 isInside/assertInside/jailJoin via path.join/resolve+startsWith (win32 toLowerCase at runtime-paths.ts:48), homedir injection + ASTRA_MODELS_DIR/ASTRA_DB_PATH env overrides; tools/src/entitydir.ts:78 + tools/src/commands/doctor.ts:212 delegate to it (no HOME/.astra string concat).
  • Production fail-closed — runtime/daemon/src/runtime.ts:253 isProduction(profile) → RangeError t('profile.production.mockRefused') for InMemoryMemoryStore/StubMemory/Mock* without explicit injection; boot.ts:81 warns t('profile.production.mockWarning') via fanoutSink when profile !== production && mock backend (health profiles leg at views.ts:68).
  • Secret store — platform/security/src/ selectSecretStore → NativeBackedSecretStore (DPAPI/Keychain/libsecret) vs UnavailableSecretStore fail-closed; MemoryConsentStore durable hasDurableConsent critical-tier gate at platform/desktop/src/consent.ts:1; mock stores gated ASTRA_PROFILE=test|simulation (assert*MockAllowed at platform/browser/src/adapter.ts:38 etc.).
  • Plane-correct transport — runtime/daemon/src/protocol.ts:70 DAEMON_ROUTES control 10 vs data 5, local-api.ts:87 DataPlaneGate 16, protocol.ts:70 DAEMON_ROUTE_LIST single source for health/doctor counts.
  • Typed failures — SpineError/DaemonError/GateError/ObservationError with t() i18n (runtime/shared/src/i18n.ts:555 profile.production.*), never message matching.

4. Known deferrals (not vulnerabilities)

  • Signing/notarization/updater — apps/desktop/src-tauri/tauri.conf.json:29 bundle.targets:"all" per-OS (msi/dmg/deb), createUpdaterArtifacts deferred per docs/research/godot-engine-decision.md:1 supply-chain gate (D7); CI cargo build via .github/workflows/ci.yml gates link errors but does not sign.
  • Unix secret store — win32 DPAPI real, unix Unavailable honest-degraded (security.store:UNAVAILABLE at runtime.ts:137); tracked in ADR-0015.
  • Telemetry — file+console fanout (runtime/core/src/logger.ts:39 daily ~/.astra/logs/daemon-YYYY-MM-DD.log via getLogsDir()), no OTEL/sentry export (health counters droppedDataRequests/planeViolations at views.ts:78 only).
  • Fonts — ChillRoundM/Xiaolai acknowledged but NOT vendored (apps/desktop/src/styles.css:7 + apps/web/src/styles.css:6 OFL note, docs/licenses.md deferred) — no @font-face FOIT.

5. Past advisories

None yet for 0.0.1 — future entries will cite file:line and link to the fixing commit.


If you found a potential bypass of any of the above (jail traversal, loopback escape, mock-in-production, scrub leak), treat it as a security report per §2.

There aren't any published security advisories