ADRs tagged security¶
Auto-generated by scripts/docs/generate-adr-by-tag.sh. Edit ADR Tags: lines to update.
105 ADR(s) carry this tag.
| ID | Title |
|---|---|
| ADR-0010 | Sign release artifacts keyless via Sigstore |
| ADR-0015 | CI matrix Linux/macOS/Windows with sanitizers |
| ADR-0033 | Relocate CodeQL config to .github/ |
| ADR-0037 | Protect master branch on GitHub with required checks |
| ADR-0038 | Purge upstream MATLAB MEX compiled binaries from tree |
| ADR-0039 | Pull forward runtime op-allowlist walk and model registry |
| ADR-0169 | ONNX op-allowlist — admit Loop + If with recursive subgraph scan (T6-5) |
| ADR-0171 | Bounded Loop.M trip-count guard (T6-5b) |
| ADR-0211 | Tiny-model registry schema + Sigstore --tiny-model-verify |
| ADR-0258 | ONNX op-allowlist — admit Resize for saliency / segmentation models (T7-32) |
| ADR-0263 | OSSF Scorecard policy and remediation cadence |
| ADR-0270 | libFuzzer scaffold for parser surfaces (OSSF Scorecard remediation) |
| ADR-0311 | libFuzzer harness expansion — fuzz_yuv_input + fuzz_cli_parse |
| ADR-0316 | cli_parse — handle long-only options in error() |
| ADR-0348 | Globally suppress CodeQL cpp/poorly-documented-function |
| ADR-0363 | Mend Renovate replaces Dependabot as the dependency-update bot |
| ADR-0379 | libvmaf Symbol Visibility — Hide Internal Symbols with -fvisibility=hidden |
| ADR-0382 | Y4M header parser — reject non-positive width or height before allocation |
| ADR-0404 | Keep nightly.yml + fuzz.yml red until underlying bugs land |
| ADR-0683 | Replace banned functions in vendored MCP cJSON |
| ADR-0694 | Tighten clang-tidy enforcement + confirm sanitizers as required CI gates |
| ADR-0698 | VMAFX Production Dockerfile — Multi-Arch, Image Signing, SBOM |
| ADR-0794 | Multi-Tenant Auth Gateway for vmafx-controller |
| ADR-0811 | Security hardening — CodeQL Go coverage + codeql-config |
| ADR-0840 | Fix cu_state leak on import failure and gpu_dispatch_env TOCTOU |
| ADR-0875 | GitHub Actions hardening audit (2026-05-30) |
| ADR-0878 | Trivy container scan baseline — production images run as non-root |
| ADR-0879 | Python dependency freshness sweep (2026-05-30) |
| ADR-0882 | Fuzz target audit — JSON model + DNN sidecar harness expansion |
| ADR-0887 | Reject JSON models whose per-feature arrays disagree on length |
| ADR-0889 | Vendored libsvm 3.24 audit — close header-row-ordering oob, document upstream-version policy |
| ADR-0902 | Signing and attestation audit — close residual gaps (2026-05-30) |
| ADR-0917 | cargo-deny supply-chain policy enforcement |
| ADR-0930 | Ship NetworkPolicy default-deny + Pod Security Standards "restricted" in the VMAFX Helm chart |
| ADR-0952 | Push test coverage on vendored libsvm + IQA paths the fork uses |
| ADR-0967 | MCP HTTP transport security — add auth + body limit + safer bind default (Round 26 audit A.1) |
| ADR-0969 | Helm chart — add seccompProfile default and fix node-deployment image helper (Round 26 audit B.1 + B.3) |
| ADR-0975 | Use NamedTemporaryFile in _run_vmaf_score to eliminate task-name collision risk |
| ADR-0976 | Remove dead has_norm sidecar fields and fix extract_string_array leak |
| ADR-0977 | core/tools input-reader safety — Y4M malloc-NULL check, YUV/Y4M size_t cast, bench GPU-state leaks |
| ADR-0978 | vmafx-server + pkg/score bug-audit — shutdown leak, gRPC Send-EOF surfacing, HTTP body cap, panic recovery |
| ADR-0983 | gosec sweep — fix all findings + add CI gate |
| ADR-0996 | eBPF FUSE bypass for rclone zero-copy path in vmafx-node |
| ADR-1007 | Fix C string/numeric UB cluster — NULL strcmp, size_t underflow, signed-shift overflow, snprintf truncation |
| ADR-1014 | Prometheus registry isolation for SetControllerSources |
| ADR-1017 | Go operator controller resource-allocation fixes |
| ADR-1018 | MCP exec.CommandContext + controller gRPC panic recovery |
| ADR-1021 | Constant-time session-token comparison + JWT nbf-claim validation |
| ADR-1022 | Cast dst_buf_read_sz operands to size_t in y4m_input to prevent signed-integer overflow |
| ADR-1035 | CI workflow concurrency guards and job timeouts |
| ADR-1036 | Correct SPDX license identifiers and add missing libsvm copyright |
| ADR-1042 | Containerfile hardening — non-root USER + build-time DEBIAN_FRONTEND |
| ADR-1058 | Helm chart security hardening — PDB, RBAC split, metrics NetworkPolicy, schema tightening |
| ADR-1061 | Fix depth-limit, integer-overflow, and banned-function bugs in vendored pdjson and cJSON |
| ADR-1065 | Go staticcheck r10 — poll-loop timer leak and missing body guards |
| ADR-1066 | Regression tests for the sequential-realloc double-free in libsvm |
| ADR-1075 | MCP HTTP transport POST /v1/score body-validation edge cases |
| ADR-1083 | y4m_input_fetch_frame signed-integer overflow + fread(NULL) UB fixes |
| ADR-1085 | MCP streaming backpressure — kill child processes on client disconnect |
| ADR-1086 | CI Workflow Least-Privilege Permissions Audit |
| ADR-1088 | CLI flag-parsing hardening — parse_unsigned overflow/negative guards and --help in cli_parse.cpp |
| ADR-1089 | Block non-standard ONNX operator domains in the DNN wire scanner |
| ADR-1090 | Fix CUDA stream and event leaks on init error paths |
| ADR-1129 | Align release containers with the published tag and runtime ABI |
| ADR-1222 | In-code suppressions do not close code-scanning alerts; scope the scan instead |
| ADR-1231 | Container bases and toolchain versions come from one config file |
| ADR-1238 | Require the Go security and test job through impact routing |
| ADR-1247 | Bind Scorecard gates to their measured source and scope |
| ADR-1248 | Enforce repository security through public rulesets |
| ADR-1252 | Declare the single maintainer's bypass actor |
| ADR-1270 | Bound repository subprocess execution behind one validated API |
| ADR-1271 | Pass NEO GitHub credentials through optional BuildKit secrets |
| ADR-1276 | Re-pin the Pelorus mirror for released parser safety fixes |
| ADR-1288 | An MCP tool schema that fails to marshal is fatal, never defaulted |
| ADR-1297 | Every check that reports on a pull request is a required context |
| ADR-1305 | Hash-locked Python dependency installs and OpenSSF supply-chain hardening |
| ADR-1306 | Replace nvidia/cuda base images with digest-pinned Ubuntu and version-locked apt installation |
| ADR-1307 | Pure SHA-256 memoization keys with cold cache invalidation |
| ADR-1308 | Resolve CodeQL float equality alerts via contract-preserving comparisons |
| ADR-1309 | Owner-only sidecar socket with identity-checked lifecycle |
| ADR-1314 | Keep unpinned Semgrep registry results advisory |
| ADR-1319 | Admit self-hosted GPU jobs through a live fail-closed probe |
| ADR-1333 | Meson test environment secret sanitization |
| ADR-1337 | C++ Placement New Visibility — Hide Inline Run-time Symbols |
| ADR-1356 | Release provenance from GitHub build-provenance attestations, not slsa-github-generator |
| ADR-1388 | Exempt PAT-mode release PRs from authoring-discipline gates via verified release-only diff |
| ADR-1389 | Run CodeQL (Actions) unconditionally on every pull request for universal SAST coverage |
| ADR-1504 | Decline praetor's branch ruleset; the policy file is the only declaration |
| ADR-1506 | Move the praetor pin to 0af07a733e65 to drop the braces chain from the documentation gate's lock |
| ADR-1518 | The controller authorises every gRPC call against one per-method role table, and a method without an entry is refused |
| ADR-1519 | The controller reads its tenants from VmafxTenant resources (or a file of them), verifies each token against its own tenant's provider, and refuses what it cannot verify |
| ADR-1522 | Every job read of the controller is scoped to the caller's tenant in the query, and a node session belongs to the tenant that registered it |
| ADR-1524 | vmafx-node pulls work from the controller, advertises exactly the backend it runs, and refuses to start when it cannot honour its configuration |
| ADR-1539 | vmafx-node starts the eBPF descriptor tracker on request, fails closed when the host cannot run it, and ships the compiled BPF object |
| ADR-1563 | a dedicated vmafx:node role is the only role that reaches the controller's node API |
| ADR-1569 | the operator presents a bearer token to the controller from a file it reads on every call, through credentials shared with the node |
| ADR-1577 | each tenant scores only inputs under its own scoring roots, denied by default, checked by the controller and again by the node |
| ADR-1592 | the controller runs under its own service account, the only one that may read VmafxTenants |
| ADR-1593 | the node image carries FUSE mount tools, and the Helm chart grants FUSE and the eBPF tracker per value |
| ADR-1686 | a Scorecard master run whose master moved on to a descendant ends cancelled |
| ADR-1886 | torch only where training runs |
| ADR-1899 | govulncheck at symbol level, OpenVEX for what is not called |
| ADR-2126 | Declare the single-maintainer gaps of OpenSSF Scorecard's Code-Review and Branch-Protection checks as exceptions |
| ADR-2350 | The VMAFx platform keeps its state in PostgreSQL, scales on queue depth and generates its platform surfaces from a definition |
| ADR-2647 | the operator records events in every namespace through a write-only ClusterRole |