• Joined on 2025-07-20
michael commented on issue dutchcoders/transfer.sh#194 2026-01-19 18:29:22 +00:00
Feature Request: environment variable for max storage size and duration.

@Leopere commented on GitHub:

So the amount of time a file is stored and shared on the TransferSH instance before its purged.

michael commented on issue usnistgov/macos_security#140 2026-01-19 18:29:22 +00:00
iCloud privacy relay disable not working

@robertgendler commented on GitHub:

@mani2care open a feedback with Apple. Unfortunately, almost none of the iCloud controls will turn the feature off. It just disables the ability to toggle…

michael opened issue usnistgov/macos_security#135 2026-01-19 18:29:21 +00:00
Remove multiple NTP servers from system_settings_time_server_configure.yaml
michael closed issue usnistgov/macos_security#133 2026-01-19 18:29:21 +00:00
Different payload type for system_settings_screensaver_timeout_enforce
michael commented on issue dutchcoders/transfer.sh#187 2026-01-19 18:29:21 +00:00
Add option to disable inline handler

@paolafrancesca commented on GitHub:

@stek29 I think that instead of disabling the inline handler we could sanitize the html content using bluemonday (https://github.com/microcosm-cc/bluemonday). …

michael commented on issue dutchcoders/transfer.sh#187 2026-01-19 18:29:21 +00:00
Add option to disable inline handler

@stek29 commented on GitHub:

Is content type sanitized in any way? MIME types are case insensitive afaik, and from what i see it’s not lowercased anywhere

michael commented on issue dutchcoders/transfer.sh#187 2026-01-19 18:29:21 +00:00
Add option to disable inline handler

@paolafrancesca commented on GitHub:

you are right @stek29 : https://github.com/dutchcoders/transfer.sh/blob/master/server/handlers.go#L476-L480

I forgot that we use mime.TypeByExtension

michael commented on issue usnistgov/macos_security#134 2026-01-19 18:29:21 +00:00
system_settings_apple_watch_unlock_disable & system_settings_touchid_unlock_disable should not be mapped to AC-11

@golbiga commented on GitHub:

This has been resolved.

michael commented on issue usnistgov/macos_security#134 2026-01-19 18:29:21 +00:00
system_settings_apple_watch_unlock_disable & system_settings_touchid_unlock_disable should not be mapped to AC-11

@robertgendler commented on GitHub:

Updating to IA-5 with note to NIST 800-63 and biometric approved and strength.

michael opened issue dutchcoders/transfer.sh#192 2026-01-19 18:29:21 +00:00
Docker compose
michael opened issue usnistgov/macos_security#133 2026-01-19 18:29:21 +00:00
Different payload type for system_settings_screensaver_timeout_enforce
michael closed issue dutchcoders/transfer.sh#191 2026-01-19 18:29:21 +00:00
disclaimer needs update?
michael closed issue dutchcoders/transfer.sh#192 2026-01-19 18:29:21 +00:00
Docker compose
michael opened issue usnistgov/macos_security#136 2026-01-19 18:29:21 +00:00
Bug: syslog daemon changes break its usage on macOS 10.13 and above
michael opened issue usnistgov/macos_security#137 2026-01-19 18:29:21 +00:00
Add baseline tags to supplemental rules
michael opened issue usnistgov/macos_security#138 2026-01-19 18:29:21 +00:00
build/cis_lvl1/cis_lvl1_compliance.sh: line 6359: syntax error near unexpected token `fi'
michael closed issue usnistgov/macos_security#136 2026-01-19 18:29:21 +00:00
Bug: syslog daemon changes break its usage on macOS 10.13 and above
michael closed issue usnistgov/macos_security#137 2026-01-19 18:29:21 +00:00
Add baseline tags to supplemental rules
michael closed issue dutchcoders/transfer.sh#190 2026-01-19 18:29:21 +00:00
Add \r\n in http-response's body
michael opened issue usnistgov/macos_security#134 2026-01-19 18:29:21 +00:00
system_settings_apple_watch_unlock_disable & system_settings_touchid_unlock_disable should not be mapped to AC-11