ranade-oss rejects a paper-thin security sync

A proposed review found that inherited code is not proof that a fork is safe to run for real users.

securitymulti-tenant

The fork considered whether its existing security and profile work truly matched an upstream package covering hosted-service protections, multi-factor-aware accounts, and encrypted personal AI-provider keys.

Rather than copy in a large upstream patch, the proposal called for testing the fork as it now stands, including:

  • Account profiles and multi-factor access controls.
  • Encrypted personal keys for AI services, with safeguards against accidental disclosure.
  • Separation between customers' data, plus deletion and key-rotation failure handling.
  • Public-facing protections such as rate limits, browser access rules, and deployment checks.

That review never happened: the pull request was closed without merging or validating the plan.

So what Legal teams assessing ROSS for sensitive client work should treat these protections as unverified until the proposed security review is completed.

View this fork on GitHub →

Spotted something wrong? Or know the PR text has fresher detail than the writeup above?