Security fixes are applied to the latest commit on main.
Please do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting feature on the repository's Security tab. Include the affected route or component, reproduction steps, impact, and any suggested mitigation.
This repository is a local observability simulation, not a production monitoring agent.
- It has no cloud credentials, shell execution, infrastructure mutation, or remediation endpoints.
- Scenario selection is a stateless read-only query; unknown scenarios fail closed.
- The API accepts JSON bodies up to 32 KB, disables the Express technology header, and returns generic internal-error responses.
- Runbooks are bundled local JSON. No remote content is fetched or executed.
- Runtime spans and logs are held in bounded process memory and disappear on restart.
- The Docker Compose profile runs with a read-only filesystem and
no-new-privileges.
Before connecting this project to real telemetry, add authentication, authorization, rate limiting, encrypted transport, retention controls, secret management, data redaction, and an approved threat model.