From 35c7b42ab1a4e932285b85804f44801f1ffb7a24 Mon Sep 17 00:00:00 2001 From: Garrett Allen <98648590+Gerrrt@users.noreply.github.com> Date: Wed, 26 Aug 2026 04:45:48 +0000 Subject: [PATCH] Record the pending GitHub GC request in the exposure ledger MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The 2026-08-19 history rewrite (021d2b6) is recorded here as "purged from history", which is true of every reachable commit but not of what GitHub still serves. Verified 2026-08-26: 647d90a, 21afcad, efb2632 and ee3d443 all still resolve through the API, and the tree at 21afcad still lists the two private keys. That is the purge runbook's "Afterwards" step — ask Support to run GC — and it was the last one outstanding with no written trace. Requested 2026-08-26; this row is where its state lives until it lands. Written as an exposure row rather than a task, because the gap was in the record: the existing rows imply the objects are gone. It says explicitly that credential status is unchanged, since rotation preceded the rewrite, so a pending GC is not mistaken later for an unremediated leak. Co-Authored-By: Claude Opus 5 --- SECURITY.md | 1 + 1 file changed, 1 insertion(+) diff --git a/SECURITY.md b/SECURITY.md index 90c439e..451ac31 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -43,6 +43,7 @@ is a very different thing from an overlooked one. Full detail in | Passphrase-encrypted TLS private keys under `certificates/` | Removed from `HEAD` and purged from history. A new CA and leaf have been generated with [`scripts/gen-certs.sh`](scripts/gen-certs.sh); the old keys are superseded and should be treated as compromised wherever they were ever trusted. | | Decrypted secrets in editor undo files, written by `make secrets-edit` | Found 2026-08-20: three files under `~/.local/state/nvim/undodir/` holding the live pfSense, APC and iLO SNMP communities in plaintext, mode 664. Shredded. `make secrets-edit` now hardens `$EDITOR` before handing it plaintext, so it cannot recur. Never committed and never left the host, so those three communities were not rotated on that basis. | | Alertmanager webhook URL and the MokerLink SNMP community, in a local Claude Code session transcript | Found 2026-08-20 by a value-level sweep of the host. Redacted in place; mode 600, never committed or synced. The webhook topic was rotated — on the public ntfy instance the topic name *is* the credential, there is nothing to revoke — and delivery re-verified end to end. The switch community deliberately was not: rotating it means the `neo` residual above all over again. | +| Pre-purge objects still served by GitHub after the history rewrite | The 2026-08-19 rewrite (`021d2b6`) removed both secrets above from every *reachable* commit, but GitHub still serves the orphaned objects by SHA. Verified 2026-08-26: `647d90a`, `21afcad`, `efb2632` and `ee3d443` all still resolve through the API, and the tree at `21afcad` still lists `certificates/Gandalf.Gondor.Lab/ca-key.pem` and `cert-key.pem`. Garbage collection requested from GitHub Support on 2026-08-26 — **pending**; this is the [purge runbook](docs/runbooks/purge-git-history.md)'s *Afterwards* step, and it is the last one outstanding. The repository has no forks and a network count of 0, so nothing else is perpetuating them. Both credentials were rotated *before* the rewrite, so this changes nothing about their status: the old keys and the old community remain superseded and must still be treated as public. Re-check with `gh api repos/Gerrrt/HomeLab/commits/647d90a --jq .sha` — a `404` means GitHub has collected them. | | The monitoring host's disk and swap are unencrypted | **Accepted residual, not a fix in progress** — see below. | The switch is the honest gap, and it is a deliberate one. `neo` (10.7.7.2) is