Action Center4
HighFix proposedNot run
northstar/core-platformdeploy/worker.yaml:66
Confidence
Confirmed
Owner
Jon Bell
First observed
25 Aug 2026, 07:02 UTC
SLA remaining
21h
Source run
RUN-8842
Fingerprint
fp:jwt.ts:38:91b2f1

Why this matters

Human-readable impact grounded in the verified target snapshot

A production signing key is committed to source and reachable by the authentication service.

An actor with repository read access could mint trusted session tokens. Rotation alone is insufficient until the committed key is removed from history and dependent credentials are invalidated.

Entry pointPOST /v1/session
Runtime pathauth-api → jwt.sign
EnvironmentProduction
ExploitabilityConfirmed

Evidence

Source provenance and integrity for every claim

1 verified artifact
No evidence artifacts are available for this fixture.