Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: edge cases

...

  • Are logs intended to be safe to expose to users with read-only authorization, or may they contain credentials?
  • If your project has a web interface, are users who have an account with 'admin' authorization on the web interface also trusted to trigger arbitrary OS commands?

For particularly tricky edge cases, you could explicitly state that while you don't guarantee a certain type of safety, you do strive for it, and will still welcome reports about such cases since you intend to fix those as security hardening improvements.