Closing as duplicate of #30 — same gdpr-no-delete-endpoint heuristic on the same dashboard user model; tracked once in #30.
Closing as duplicate of #30 — same gdpr-no-delete-endpoint heuristic on the same dashboard user model; tracked once in #30.
Keeping this as the single tracking issue for GDPR data-deletion capability for dashboard users (auth.rs / user_state.rs). #31 and #32 were the same heuristic firing on adjacent code and are…
Closing as duplicate of #29 (same rule writable-filesystem-service, same file deploy/docker-compose.mailserver.yml), now consolidated into #28.
Consolidating mailserver docker-compose hardening here: in addition to no-new-privileges:true (this issue), also add read_only: true with tmpfs for temp paths (was #29 / #54, closed as…
Closing: consolidated into #28 (single mailserver compose hardening issue covering no-new-privileges + read_only rootfs).