<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Security on Arivu</title>
		<link>https://arivu.app/tags/security/</link>
		<description>Recent content in Security on Arivu</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
		
			<lastBuildDate>Wed, 08 Jul 2026 00:00:00 +0000</lastBuildDate>
		
			<atom:link href="https://arivu.app/tags/security/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Safer Self-Hosting, Less Guesswork</title>
				<link>https://arivu.app/chronicle/safer-self-hosting-less-guesswork/</link>
				<pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
				<guid>https://arivu.app/chronicle/safer-self-hosting-less-guesswork/</guid>
				<description>&lt;blockquote&gt;&#xA;&lt;p&gt;&lt;strong&gt;Context, 2026-07-13:&lt;/strong&gt; Upgrades are additive-safe, preserve executable permissions under restrictive defaults, and provide useful activation diagnostics when a replacement cannot start. Existing data and configuration remain in place.&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;&lt;strong&gt;Update, July 11, 2026:&lt;/strong&gt; The installer no longer requires GitHub CLI. Piped bootstrap keeps interactive prompts TTY-safe, DNS mismatches produce actionable warnings, and newer Ubuntu releases are tolerated rather than rejected only for being newer. Upgrades now verify and transactionally activate the matching app and installer binaries, roll both back if activation fails, and prompt browsers to revalidate embedded frontend assets. Tagged releases report the exact release version; development builds may report development metadata. Public HTTPS can still require correct DNS, firewall, or shared-proxy configuration.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Quieter Admin, Stronger Guarantees</title>
				<link>https://arivu.app/chronicle/admin-and-guarantees/</link>
				<pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
				<guid>https://arivu.app/chronicle/admin-and-guarantees/</guid>
				<description>&lt;p&gt;Before we ship a wave of new features, we wanted the operating layer underneath them to be solid. This update rebuilds the admin experience on the app&amp;rsquo;s own storage, makes provider configuration a runtime concern instead of a restart concern, and adds a clear audit trail for sensitive actions.&lt;/p&gt;&#xA;&lt;p&gt;None of this changes what Arivu looks like day to day. It changes how confidently you can run it.&lt;/p&gt;&#xA;&lt;svg viewBox=&#34;0 0 700 200&#34; xmlns=&#34;http://www.w3.org/2000/svg&#34; style=&#34;max-width: 100%; height: auto; display: block; margin: 2rem auto;&#34; role=&#34;img&#34; aria-labelledby=&#34;chronicle-admin-and-guarantees-1-title chronicle-admin-and-guarantees-1-desc&#34;&gt;&#xA;  &lt;title id=&#34;chronicle-admin-and-guarantees-1-title&#34;&gt;Quieter Admin, Stronger Guarantees, diagram 1&lt;/title&gt;&#xA;  &lt;desc id=&#34;chronicle-admin-and-guarantees-1-desc&#34;&gt;Historical diagram 1 accompanying the Chronicle post Quieter Admin, Stronger Guarantees.&lt;/desc&gt;&#xA;&lt;rect x=&#34;30&#34; y=&#34;30&#34; width=&#34;150&#34; height=&#34;80&#34; fill=&#34;#CF3F1E&#34; stroke=&#34;#2F2E2B&#34; stroke-width=&#34;2&#34;/&gt;&#xA;&lt;text x=&#34;105&#34; y=&#34;62&#34; font-family=&#34;&#39;Geist Mono&#39;, monospace&#34; font-size=&#34;11&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34; font-weight=&#34;bold&#34;&gt;ADMIN&lt;/text&gt;&#xA;&lt;text x=&#34;105&#34; y=&#34;80&#34; font-family=&#34;&#39;Geist&#39;, sans-serif&#34; font-size=&#34;9&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34;&gt;Overview, users,&lt;/text&gt;&#xA;&lt;text x=&#34;105&#34; y=&#34;94&#34; font-family=&#34;&#39;Geist&#39;, sans-serif&#34; font-size=&#34;9&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34;&gt;system, activity&lt;/text&gt;&#xA;&lt;rect x=&#34;200&#34; y=&#34;30&#34; width=&#34;150&#34; height=&#34;80&#34; fill=&#34;#7E2412&#34; stroke=&#34;#2F2E2B&#34; stroke-width=&#34;2&#34;/&gt;&#xA;&lt;text x=&#34;275&#34; y=&#34;62&#34; font-family=&#34;&#39;Geist Mono&#39;, monospace&#34; font-size=&#34;11&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34; font-weight=&#34;bold&#34;&gt;SETTINGS&lt;/text&gt;&#xA;&lt;text x=&#34;275&#34; y=&#34;80&#34; font-family=&#34;&#39;Geist&#39;, sans-serif&#34; font-size=&#34;9&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34;&gt;Runtime provider&lt;/text&gt;&#xA;&lt;text x=&#34;275&#34; y=&#34;94&#34; font-family=&#34;&#39;Geist&#39;, sans-serif&#34; font-size=&#34;9&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34;&gt;keys, no restart&lt;/text&gt;&#xA;&lt;rect x=&#34;370&#34; y=&#34;30&#34; width=&#34;150&#34; height=&#34;80&#34; fill=&#34;#7E2412&#34; stroke=&#34;#2F2E2B&#34; stroke-width=&#34;2&#34;/&gt;&#xA;&lt;text x=&#34;445&#34; y=&#34;62&#34; font-family=&#34;&#39;Geist Mono&#39;, monospace&#34; font-size=&#34;11&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34; font-weight=&#34;bold&#34;&gt;AUDIT&lt;/text&gt;&#xA;&lt;text x=&#34;445&#34; y=&#34;80&#34; font-family=&#34;&#39;Geist&#39;, sans-serif&#34; font-size=&#34;9&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34;&gt;Sensitive actions&lt;/text&gt;&#xA;&lt;text x=&#34;445&#34; y=&#34;94&#34; font-family=&#34;&#39;Geist&#39;, sans-serif&#34; font-size=&#34;9&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34;&gt;recorded&lt;/text&gt;&#xA;&lt;rect x=&#34;540&#34; y=&#34;30&#34; width=&#34;150&#34; height=&#34;80&#34; fill=&#34;#2F2E2B&#34; stroke=&#34;#2F2E2B&#34; stroke-width=&#34;2&#34;/&gt;&#xA;&lt;text x=&#34;615&#34; y=&#34;62&#34; font-family=&#34;&#39;Geist Mono&#39;, monospace&#34; font-size=&#34;11&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34; font-weight=&#34;bold&#34;&gt;SUPPLY CHAIN&lt;/text&gt;&#xA;&lt;text x=&#34;615&#34; y=&#34;80&#34; font-family=&#34;&#39;Geist&#39;, sans-serif&#34; font-size=&#34;9&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34;&gt;Verified builds,&lt;/text&gt;&#xA;&lt;text x=&#34;615&#34; y=&#34;94&#34; font-family=&#34;&#39;Geist&#39;, sans-serif&#34; font-size=&#34;9&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34;&gt;pinned scans&lt;/text&gt;&#xA;&lt;rect x=&#34;30&#34; y=&#34;135&#34; width=&#34;660&#34; height=&#34;45&#34; fill=&#34;#FDFCF9&#34; stroke=&#34;#2F2E2B&#34; stroke-width=&#34;2&#34;/&gt;&#xA;&lt;text x=&#34;360&#34; y=&#34;162&#34; font-family=&#34;&#39;Geist Mono&#39;, monospace&#34; font-size=&#34;10&#34; fill=&#34;#2F2E2B&#34; text-anchor=&#34;middle&#34; font-weight=&#34;bold&#34;&gt;ONE GO APP, ONE SQLITE DATABASE, ONE PLACE TO LOOK&lt;/text&gt;&#xA;&lt;/svg&gt;&#xA;&lt;h2 id=&#34;a-native-admin-dashboard&#34;&gt;A Native Admin Dashboard&lt;/h2&gt;&#xA;&lt;p&gt;The admin dashboard now runs entirely on the app&amp;rsquo;s own SQLite storage. Admins listed in &lt;code&gt;ADMIN_EMAILS&lt;/code&gt; get an &lt;code&gt;/admin&lt;/code&gt; area with sections for overview, API usage, users, system status, recent activity, collections, and an audit log.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Arivu Is Simpler to Self-Host Now</title>
				<link>https://arivu.app/chronicle/simpler-self-hosting-go-rewrite/</link>
				<pubDate>Mon, 15 Jun 2026 00:00:00 +0000</pubDate>
				<guid>https://arivu.app/chronicle/simpler-self-hosting-go-rewrite/</guid>
				<description>&lt;p&gt;Arivu is moving in a simpler direction.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Update, July 2026:&lt;/strong&gt; Since this post, Arivu added a first-party Linux VPS installer with plan, backup, restore, upgrade, reconfigure, and shared-proxy modes. The Go and SQLite runtime shape below is still current, but the recommended production path is now covered in &lt;a href=&#34;https://arivu.app/chronicle/safer-self-hosting-less-guesswork/&#34;&gt;Safer Self-Hosting, Less Guesswork&lt;/a&gt; and the guided &lt;a href=&#34;https://arivu.app/documentation/self-hosting-arivu/&#34;&gt;self-hosting guide&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The app is now rebuilt around one Go application that serves the web UI, API, background workers, CLI commands, and migration tooling. The shipped frontend is embedded into the binary. Persistence is SQLite. Provider integrations use direct HTTP calls. The result is a self-hosted Arivu that has fewer pieces to run, fewer dependency trees to audit, and a clearer operational model.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Arivu From the Terminal</title>
				<link>https://arivu.app/chronicle/arivu-cli-terminal-workflow/</link>
				<pubDate>Sun, 10 May 2026 00:00:00 +0000</pubDate>
				<guid>https://arivu.app/chronicle/arivu-cli-terminal-workflow/</guid>
				<description>&lt;p&gt;Arivu started as a web app and browser extension because that is where most bookmarking happens. But a second brain should not disappear the moment you leave the browser. Research, writing, operations work, and development all move through the terminal too.&lt;/p&gt;&#xA;&lt;p&gt;The new Arivu CLI brings the same intelligence layer to command-line workflows. You can save links, search by meaning, inspect bookmarks, import exports, check reading stats, manage local profiles, explore graph connections, and boot a local Arivu stack without switching context.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Automated Security, Testing, and Code Quality</title>
				<link>https://arivu.app/chronicle/security-quality-automation/</link>
				<pubDate>Sun, 08 Mar 2026 00:00:00 +0000</pubDate>
				<guid>https://arivu.app/chronicle/security-quality-automation/</guid>
				<description>&lt;p&gt;&lt;strong&gt;Historical note, July 2026:&lt;/strong&gt; This post reflects the automation used by the earlier Python and JavaScript stack. The current Go-based app uses a different, smaller dependency surface and validation workflow. The product-level commitment still stands: automated checks should catch security, quality, and regression issues before release.&lt;/p&gt;&#xA;&lt;p&gt;With the codebase now open source, we invested in the automation that keeps it healthy. This update adds continuous integration pipelines, automated dependency monitoring, static analysis, and a frontend test suite - the kind of infrastructure that catches problems before they reach you.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Production Hardening: Security, Speed, and Structure</title>
				<link>https://arivu.app/chronicle/production-hardening/</link>
				<pubDate>Thu, 05 Feb 2026 00:00:00 +0000</pubDate>
				<guid>https://arivu.app/chronicle/production-hardening/</guid>
				<description>&lt;p&gt;Arivu is now more secure, faster, and easier to evolve. This update focuses on the invisible infrastructure work that separates a side project from a production-ready product.&lt;/p&gt;&#xA;&lt;p&gt;We completed a comprehensive hardening pass across three domains: authentication security, database performance, and code architecture. Here&amp;rsquo;s what changed and why it matters.&lt;/p&gt;&#xA;&lt;svg viewBox=&#34;0 0 700 140&#34; xmlns=&#34;http://www.w3.org/2000/svg&#34; style=&#34;max-width: 100%; height: auto; display: block; margin: 2rem auto;&#34; role=&#34;img&#34; aria-labelledby=&#34;chronicle-production-hardening-1-title chronicle-production-hardening-1-desc&#34;&gt;&#xA;  &lt;title id=&#34;chronicle-production-hardening-1-title&#34;&gt;Production Hardening: Security, Speed, and Structure, diagram 1&lt;/title&gt;&#xA;  &lt;desc id=&#34;chronicle-production-hardening-1-desc&#34;&gt;Historical diagram 1 accompanying the Chronicle post Production Hardening: Security, Speed, and Structure.&lt;/desc&gt;&#xA;  &lt;rect x=&#34;60&#34; y=&#34;40&#34; width=&#34;160&#34; height=&#34;80&#34; fill=&#34;#CF3F1E&#34; stroke=&#34;#2F2E2B&#34; stroke-width=&#34;2&#34;/&gt;&#xA;  &lt;text x=&#34;140&#34; y=&#34;70&#34; font-family=&#34;&#39;Geist Mono&#39;, monospace&#34; font-size=&#34;12&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34; font-weight=&#34;bold&#34;&gt;SECURITY&lt;/text&gt;&#xA;  &lt;text x=&#34;140&#34; y=&#34;90&#34; font-family=&#34;&#39;Geist&#39;, sans-serif&#34; font-size=&#34;10&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34;&gt;Auth hardening&lt;/text&gt;&#xA;  &lt;text x=&#34;140&#34; y=&#34;105&#34; font-family=&#34;&#39;Geist&#39;, sans-serif&#34; font-size=&#34;10&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34;&gt;Transport protection&lt;/text&gt;&#xA;  &lt;rect x=&#34;270&#34; y=&#34;40&#34; width=&#34;160&#34; height=&#34;80&#34; fill=&#34;#7E2412&#34; stroke=&#34;#2F2E2B&#34; stroke-width=&#34;2&#34;/&gt;&#xA;  &lt;text x=&#34;350&#34; y=&#34;70&#34; font-family=&#34;&#39;Geist Mono&#39;, monospace&#34; font-size=&#34;12&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34; font-weight=&#34;bold&#34;&gt;PERFORMANCE&lt;/text&gt;&#xA;  &lt;text x=&#34;350&#34; y=&#34;90&#34; font-family=&#34;&#39;Geist&#39;, sans-serif&#34; font-size=&#34;10&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34;&gt;Query optimization&lt;/text&gt;&#xA;  &lt;text x=&#34;350&#34; y=&#34;105&#34; font-family=&#34;&#39;Geist&#39;, sans-serif&#34; font-size=&#34;10&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34;&gt;Connection efficiency&lt;/text&gt;&#xA;  &lt;rect x=&#34;480&#34; y=&#34;40&#34; width=&#34;160&#34; height=&#34;80&#34; fill=&#34;#2F2E2B&#34; stroke=&#34;#2F2E2B&#34; stroke-width=&#34;2&#34;/&gt;&#xA;  &lt;text x=&#34;560&#34; y=&#34;70&#34; font-family=&#34;&#39;Geist Mono&#39;, monospace&#34; font-size=&#34;12&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34; font-weight=&#34;bold&#34;&gt;ARCHITECTURE&lt;/text&gt;&#xA;  &lt;text x=&#34;560&#34; y=&#34;90&#34; font-family=&#34;&#39;Geist&#39;, sans-serif&#34; font-size=&#34;10&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34;&gt;Modular structure&lt;/text&gt;&#xA;  &lt;text x=&#34;560&#34; y=&#34;105&#34; font-family=&#34;&#39;Geist&#39;, sans-serif&#34; font-size=&#34;10&#34; fill=&#34;#FDFCF9&#34; text-anchor=&#34;middle&#34;&gt;Safer iteration&lt;/text&gt;&#xA;&lt;/svg&gt;&#xA;&lt;h2 id=&#34;security&#34;&gt;Security&lt;/h2&gt;&#xA;&lt;p&gt;Your account is now protected against brute-force password attacks. Repeated failed login attempts trigger a temporary lockout, stopping automated guessing while letting legitimate users recover naturally.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Fortified &amp; Fresh</title>
				<link>https://arivu.app/chronicle/security-aging-indicators/</link>
				<pubDate>Mon, 29 Dec 2025 00:00:00 +0000</pubDate>
				<guid>https://arivu.app/chronicle/security-aging-indicators/</guid>
				<description>&lt;p&gt;Bookmarks don&amp;rsquo;t die, they just get buried. You save something brilliant, fully intending to return to it, and then&amp;hellip; three months pass. Six months. A year. That article about distributed systems? Still sitting there, unread, slowly becoming irrelevant.&lt;/p&gt;&#xA;&lt;p&gt;The problem isn&amp;rsquo;t that you don&amp;rsquo;t care. It&amp;rsquo;s that nothing reminds you.&lt;/p&gt;&#xA;&lt;p&gt;Most bookmark managers treat every link the same: a flat list ordered by date, maybe grouped into folders you created with good intentions. There&amp;rsquo;s no concept of urgency, no sense that some bookmarks are aging out of relevance while others remain evergreen. Your collection becomes a timeline of abandoned intentions.&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
