forked from username/flaskpaste
docs: update documentation after pentest remediation
- TASKLIST.md: add pentest tasks to completed section - TODO.md: add observation about pentest completion - ROADMAP.md: update test count (301), add decision log entry - PROJECT.md: update test count (301) - SECURITY.md: remove obsolete limitations, add v1.5.0 changes
This commit is contained in:
1
TODO.md
1
TODO.md
@@ -17,6 +17,7 @@ Unstructured intake buffer for ideas, issues, and observations. Items here are r
|
||||
|
||||
## Observations
|
||||
|
||||
- Comprehensive pentest plan completed (PENTEST_PLAN.md) - all remediations implemented
|
||||
- PKI uses AES-256-GCM for CA private key encryption (PBKDF2 key derivation)
|
||||
- SHA1 fingerprints are X.509 standard, not security-relevant (usedforsecurity=False)
|
||||
- Revoked certificates are soft-deleted (status tracked, not removed)
|
||||
|
||||
Reference in New Issue
Block a user