You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: README.md
+10-10Lines changed: 10 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,11 +9,11 @@
9
9
<p><strong>Learn from the work you're already doing</strong></p>
10
10
11
11
<p>
12
-
<a href="https://hephaestus.aet.cit.tum.de"><img alt="Open the TUM-operated Hephaestus web app" src="https://img.shields.io/badge/web_app-try_it-493C83"></a>
12
+
<a href="https://hephaestus.build"><img alt="Open the TUM-operated Hephaestus web app" src="https://img.shields.io/badge/web_app-try_it-493C83"></a>
13
13
<a href="https://docs.hephaestus.build/"><img alt="Read the Hephaestus documentation" src="https://img.shields.io/badge/docs-read_online-1F75CB?logo=docusaurus&logoColor=white"></a>
Copy file name to clipboardExpand all lines: SECURITY.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@
4
4
5
5
**Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.**
6
6
7
-
Report privately via [GitHub private vulnerability reporting](https://github.com/ls1intum/Hephaestus/security/advisories/new) — it keeps the report confidential and credits you in the resulting advisory. If you cannot use GitHub, email [felixtj.dietrich@tum.de](mailto:felixtj.dietrich@tum.de) with the subject "Hephaestus Security Vulnerability Report".
7
+
Report privately via [GitHub private vulnerability reporting](https://github.com/hephaestus-build/Hephaestus/security/advisories/new) — it keeps the report confidential and credits you in the resulting advisory. If you cannot use GitHub, email [felixtj.dietrich@tum.de](mailto:felixtj.dietrich@tum.de) with the subject "Hephaestus Security Vulnerability Report".
8
8
9
9
Please include as much as you can:
10
10
@@ -19,7 +19,7 @@ Security reports are triaged before other work.
19
19
20
20
-**Initial response within 14 days.**
21
21
- We follow **coordinated disclosure**: please give us time to ship a fix before disclosing publicly. If we cannot agree on a timeline, we treat **90 days** from your report as the default disclosure date, shortened when a vulnerability is being actively exploited.
22
-
- Confirmed vulnerabilities are fixed as soon as feasible and published as [GitHub Security Advisories](https://github.com/ls1intum/Hephaestus/security/advisories). You are credited unless you prefer to stay anonymous.
22
+
- Confirmed vulnerabilities are fixed as soon as feasible and published as [GitHub Security Advisories](https://github.com/hephaestus-build/Hephaestus/security/advisories). You are credited unless you prefer to stay anonymous.
23
23
24
24
We do not run a bug bounty program.
25
25
@@ -53,4 +53,4 @@ Independent of this reporting channel, the project runs:
53
53
-**Static analysis**: GitHub CodeQL
54
54
-**Native alerts**: GitHub secret scanning and Dependabot dependency alerts
55
55
56
-
A machine-readable [`security.txt`](https://hephaestus.aet.cit.tum.de/.well-known/security.txt) ([RFC 9116](https://www.rfc-editor.org/info/rfc9116/)) points to this policy.
56
+
A machine-readable [`security.txt`](https://hephaestus.build/.well-known/security.txt) ([RFC 9116](https://www.rfc-editor.org/info/rfc9116/)) points to this policy.
Copy file name to clipboardExpand all lines: docs/admin/dsms/README.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ description: Art. 30 / Art. 35 / Art. 28 records and source-governance controls
7
7
8
8
# Hephaestus — Data-Protection Documentation
9
9
10
-
This folder is the data-protection package for the TUM-operated Hephaestus deployment at https://hephaestus.aet.cit.tum.de. Files are named after the GDPR articles they answer to, not after the TUM DSMS portal field labels. The portal supplies its own field prompts; submit by pasting from the fenced code blocks in `record-of-processing.md` into the corresponding form fields.
10
+
This folder is the data-protection package for the TUM-operated Hephaestus deployment at https://hephaestus.build. Files are named after the GDPR articles they answer to, not after the TUM DSMS portal field labels. The portal supplies its own field prompts; submit by pasting from the fenced code blocks in `record-of-processing.md` into the corresponding form fields.
11
11
12
12
A different operator forking Hephaestus must amend, before opening their deployment to users: the controller block in `record-of-processing.md`, the operational-contact email, the Art. 28 row for any processor they engage that is not on the AET pool, the consent / public-task framing in `record-of-processing.md` "Legal basis", and the live privacy notice and imprint under `webapp/public/legal/profiles/`.
13
13
@@ -21,7 +21,7 @@ A different operator forking Hephaestus must amend, before opening their deploym
21
21
|[`artifact-source-governance.md`](./artifact-source-governance.md)| Approval, minimization, processor-egress, retention, and erasure gate for every AI-readable source. |
22
22
|[`personal-data-map.md`](./personal-data-map.md)| Personal-data stores, export coverage, erasure paths, residual retention, and their verification. |
23
23
24
-
The live imprint and privacy pages are at https://hephaestus.aet.cit.tum.de/imprint and https://hephaestus.aet.cit.tum.de/privacy. Markdown source: [`webapp/public/legal/profiles/tumaet/`](https://github.com/ls1intum/Hephaestus/tree/main/webapp/public/legal/profiles/tumaet).
24
+
The live imprint and privacy pages are at https://hephaestus.build/imprint and https://hephaestus.build/privacy. Markdown source: [`webapp/public/legal/profiles/tumaet/`](https://github.com/hephaestus-build/Hephaestus/tree/main/webapp/public/legal/profiles/tumaet).
It is an engineering gate and contains only releasable decision summaries. Each record governs exactly one source-use purpose; a source references separate records for automated review, feedback delivery, Mentor context, and operator evidence review:
58
58
59
59
-`ENGINEERING_BASELINE` with `ENGINEERING_APPROVED` records maintainer approval of the shipped, minimized
Copy file name to clipboardExpand all lines: docs/admin/dsms/record-of-processing.md
+5-5Lines changed: 5 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
# Hephaestus — Record of Processing Activities (Art. 30 GDPR)
2
2
3
-
This file is the Art. 30 record for the TUM-operated Hephaestus deployment at https://hephaestus.aet.cit.tum.de. Each section maps to a single Art. 30 element. Fenced code blocks are paste-ready into the corresponding TUM DSMS form field at https://dsms.datenschutz.tum.de/; everything outside the fences is contextual.
3
+
This file is the Art. 30 record for the TUM-operated Hephaestus deployment at https://hephaestus.build. Each section maps to a single Art. 30 element. Fenced code blocks are paste-ready into the corresponding TUM DSMS form field at https://dsms.datenschutz.tum.de/; everything outside the fences is contextual.
4
4
5
5
## Identifier
6
6
@@ -29,7 +29,7 @@ DSMS responsible person: Stephan Krusche (krusche@tum.de). Felix Dietrich (felix
29
29
## Purpose and description (Art. 30(1)(b))
30
30
31
31
```text
32
-
Hephaestus is a self-hosted web platform operated by AET on TUM infrastructure at https://hephaestus.aet.cit.tum.de. Its purpose is to support project-based software-engineering teaching at TUM and the development work of AET research projects by giving each contributor feedback on their collaborative engineering work: for example, whether a pull request is small enough to review well, or whether a review reply addresses the question raised.
32
+
Hephaestus is a self-hosted web platform operated by AET on TUM infrastructure at https://hephaestus.build. Its purpose is to support project-based software-engineering teaching at TUM and the development work of AET research projects by giving each contributor feedback on their collaborative engineering work: for example, whether a pull request is small enough to review well, or whether a review reply addresses the question raised.
33
33
34
34
A workspace administrator connects one or more Git repositories from github.com or gitlab.lrz.de. Hephaestus then synchronises the pull/merge requests, issues, code reviews, review comments, and commit metadata authored in those repositories. The platform processes activity authored in the connected repositories, whether or not the author has signed in to Hephaestus.
35
35
@@ -93,7 +93,7 @@ U.S. recipients are covered by the EU-US Data Privacy Framework (Commission Impl
93
93
**Where stored**
94
94
95
95
```text
96
-
Self-hosted by AET at https://hephaestus.aet.cit.tum.de on AET-administered infrastructure at TUM. Application data — including authentication state (accounts, federated identity links, the cookie-session revocation list, and the auth-event log) — in PostgreSQL, which also holds the practice-review job queue; webhook and integration-sync events in NATS JetStream. Local working copies of monitored repositories may be stored on the host filesystem when practice-review code execution is enabled. Container stdout goes to the Docker json-file driver. Every service in the stack sets an explicit rotation cap in the compose files: 50 MiB per file × 5 files for the webapp, the application server, the worker and PostgreSQL; 10 MiB × 3 for the webhook receiver, NATS, the reverse proxy and the maintenance page. No layer of the stack writes an HTTP access log — Tomcat's is explicitly disabled in the production profile, the Traefik reverse proxy is not started with `--accesslog` (Traefik's default is off), and both nginx containers (the static frontend and the maintenance page) disable it at the server level. No per-request IP/URL record is created anywhere.
96
+
Self-hosted by AET at https://hephaestus.build on AET-administered infrastructure at TUM. Application data — including authentication state (accounts, federated identity links, the cookie-session revocation list, and the auth-event log) — in PostgreSQL, which also holds the practice-review job queue; webhook and integration-sync events in NATS JetStream. Local working copies of monitored repositories may be stored on the host filesystem when practice-review code execution is enabled. Container stdout goes to the Docker json-file driver. Every service in the stack sets an explicit rotation cap in the compose files: 50 MiB per file × 5 files for the webapp, the application server, the worker and PostgreSQL; 10 MiB × 3 for the webhook receiver, NATS, the reverse proxy and the maintenance page. No layer of the stack writes an HTTP access log — Tomcat's is explicitly disabled in the production profile, the Traefik reverse proxy is not started with `--accesslog` (Traefik's default is off), and both nginx containers (the static frontend and the maintenance page) disable it at the server level. No per-request IP/URL record is created anywhere.
97
97
98
98
Application and authentication data reside on TUM infrastructure within the EU. AI-assisted features additionally forward code snippets and surrounding discussion to the workspace-configured LLM provider (default for the TUM-operated deployment: Microsoft Azure OpenAI in an EU region).
99
99
```
@@ -246,8 +246,8 @@ DSMS multi-select: tick `Data received from third parties` and `Directly from th
246
246
247
247
## Information duty (Art. 13)
248
248
249
-
-https://hephaestus.aet.cit.tum.de/privacy
250
-
-https://hephaestus.aet.cit.tum.de/imprint
249
+
-https://hephaestus.build/privacy
250
+
-https://hephaestus.build/imprint
251
251
252
252
Markdown source under `webapp/public/legal/profiles/tumaet/`.
0 commit comments