Vulnerability management
Last updated 2026-09-25. Owner: founder.
1. Status
| Control | Status |
|---|---|
CI pipeline (tests, lint, type check, npm audit) on every push |
Planned — not configured. No CI workflow exists in the repository yet. |
| Dependabot (npm + GitHub Actions) | Planned — not configured. |
| GitHub secret scanning and push protection | Planned (enable when the repository is on GitHub). |
| Automated tests for tenant isolation, immutability, tamper detection, rules | Yes (src/**/*.test.ts, run locally). |
| Independent penetration test | Planned — before the first live firm, then yearly. Not done. |
| Security review of the codebase (Prompt 10) | In progress. |
2. Sources of vulnerabilities we watch
- Dependencies:
npm audit, Dependabot alerts, GitHub advisories. - Framework: Next.js, Prisma and Node.js security releases.
- Providers: security bulletins from AWS, Neon, Netlify, Stripe, Resend, Sentry.
- Our own code: tests, code review, pen test findings, reports from customers or researchers.
3. CI rules (to be put in .github/workflows/ci.yml)
On every push and pull request:
npm cinpm run lintandtsc --noEmitnpx vitest run(unit tests, then database tests against a disposable Postgres)npm audit --audit-level=high --omit=dev— fails the build on any high or critical vulnerability in production dependencies.- Deploys to production happen only from the main branch after CI passes.
Dependabot: weekly for npm and GitHub Actions, security updates immediately.
4. Patch timelines
Measured from when we learn of the issue. "Exploitable" means it can be reached in how CheckTrail uses the component.
| Severity | Examples | Fix or mitigate within |
|---|---|---|
| Critical (exploitable) | Remote code execution, auth bypass, cross-tenant data access | 48 hours (mitigate within 24) |
| High | Exploitable injection, privilege escalation, sensitive data exposure | 7 days |
| Medium | Limited-impact issues, hard to exploit | 30 days |
| Low / not reachable | Dev-only dependency, code path not used | 90 days or next routine update |
If a fix is not available, record a mitigation (config change, disabling a feature, WAF rule) and the reason. Exceptions are written down with an expiry date.
Routine updates: all dependencies reviewed and updated at least monthly.
5. Penetration testing
- Planned: an external web-application pen test covering authentication, session handling, tenant isolation, role/branch authorization, file upload, examiner links, and the cron and webhook endpoints. Before the first live firm; then yearly and after major changes.
- Budget and vendor: not chosen. Get 2–3 quotes; confirm cost before booking.
- Findings are fixed per the timelines above; a summary letter is shared with customers on request.
6. Reporting a vulnerability
Email security@
7. Records
Keep for at least 3 years: CI results, npm audit output at each release, Dependabot history, pen
test reports and remediation evidence, exceptions.