Security
pg_agent_gate is a security boundary, so a way around it is the most valuable report this project can receive.
Reporting a vulnerability
Do not open a public issue. Report it privately, by either:
- GitHub’s private vulnerability reporting: the Security tab of this repository, then Report a vulnerability; or
- email to manuelreyesbravo@gmail.com, subject starting with
[pg_agent_gate security].
Please include the PostgreSQL version, the pg_agent_gate version (SELECT
agent_gate.whoami() and SELECT extversion FROM pg_extension WHERE extname =
'pg_agent_gate'), and the smallest sequence of statements that shows it. A case
in the style of tests/*.sh – an attack plus a superuser’s check that something
changed – is ideal, because it becomes the regression test.
You will get an acknowledgement within 72 hours. A confirmed bypass is fixed
before it is disclosed, gets a regression case in tests/, and is credited to
you in the CHANGELOG unless you prefer otherwise.
What counts
Anything that lets a session registered as an agent execute SQL other than the
gate’s verbs, get a proposal past verification that should not pass, change
more rows than its max_rows, move the context its row-level policies read,
or alter the record. The threat model says what is in
scope; what it lists as trusted or not covered is known, but a clearer way to
explain it is welcome too.
Supported versions
The latest release. Fixes are not backported while the project is pre-1.0.