PacificDB Community · v1.1.2
The Community security
and reliability patch.
Open source and self-hosted. Engine, CLI, SDKs and Workbench source versions now align at 1.1.2. No subscriptions, paid feature limits or commercial control plane are added.
What is in this patch?
Added
- Database owners and explicit read-only/read-write/co-owner grants, audited recovery administration and persisted metrics-only keys.
- Native revision/hash manifests and packaged-runtime dependency checks.
- Private audit monitoring, production readiness checks, alert rules and real engine-to-Alertmanager-to-receiver failure/retry/recovery verification.
Removed
- Trust in caller-supplied database names for foreign media and in namespace names as authorization.
- Wildcard fallback for invalid listener binds, unbounded sparse-chunk scans and unchecked response/frame growth.
- Immediate lockout clearing and uninterruptible backtracking query regex matching.
Improved
- All nine findings from the original internal review are addressed with focused regressions, including nested-bulk scope and API-key role ceilings.
- Local managed listeners stay on loopback; validation and effective configuration agree.
- Denials/failures retain actor attribution; audit persistence failures, buffer loss and recovery are visible.
- Pod-IP probes verify mTLS and bounded responses. Audit failure removes readiness without forcing liveness restart loops.
- Container base digests, sandbox, backup/restore and persistence checks, release qualification and exact-version advisory policy.
Workbench and upgrade
Workbench bundles the security-remediated 1.1.2 components. Runtime checks exercise sandboxed GUI launch, CRUD/media, backups/restore and restart persistence; final artifacts must match their revision/hash manifest.
Before upgrading real data, verify an external backup and restore, retain the previous binaries, and test a copy in an isolated data directory. Existing authenticated databases without ownership metadata require explicit superadmin owner assignment. Query regex now uses RE2; backreferences/lookarounds are rejected. RE2 libraries are required for source/native builds.
Real-data and production-readiness statement
Maintainer-reported verification is complete. This is an attestation, not an independently validated certification. The patch is designed for self-hosted production operation with documented safeguards; no unconditional safety or zero-data-loss guarantee is made.
Retained evidence covers scoped security regressions, Linux sandboxed runtime and container checks, Helm/schema validation and actual local alert firing, retry and resolution. Historical eight-hour and power-cut results retain their original revision; they are not automatically proof for the final patch.
Independent exact-release review, real production deployment/operator delivery proof and final signed/notarized Windows/macOS artifacts still require attached evidence and validation. Release gates remain fail-closed. Do not use an older unsigned-release exception as approval for this version.
Enable authentication/TLS, review grants, verify backups and restore, monitor audit health, and validate your deployment before storing real data.
Dependency exception
The retained runtime npm audit reports zero advisories. Eight moderate build-only package entries have a documented, exact-version risk acceptance expiring 6 November 2026 at 00:00 UTC. They are accepted, not patched. CI rejects new/runtime/unreviewed/expired findings; reviewed build tools are excluded from application runtime code. This is not a complete native/JVM/Python/container vulnerability assessment.
Read the complete patch notes and evidence requirements. Previous 1.1.1 release.