Conversation
…ock. cargo audit: wasmtime 8.0.1 (pinned by the polkadot-sdk fork's sc-executor, like the other wasmtime entries) picked up RUSTSEC-2026-0269, a WASI filesystem sandbox escape. The runtime WASM never gets a filesystem, so the advisory is accepted alongside the existing wasmtime ignores. docs preview: npm audit flagged fast-uri 3.1.5 (four GHSAs) under the Vercel CLI tree. Pin fast-uri 3.1.7 via overrides; npm ci and npm audit --audit-level=high pass locally. Both checks have been failing on main. Co-authored-by: Cursor <cursoragent@cursor.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
🛡️ AI Review — Skeptic (security review)VERDICT: SAFE BASELINE scrutiny: established write-permission contributor with substantial merged history; no Gittensor association found; ci/audit-advisories → main. The dependency override and matching lockfile entry narrowly upgrade FindingsNo findings. ConclusionThe changes are consistent with the stated advisory remediation and introduce no credible security vulnerability or hostile execution path. 🔍 AI Review — Auditor (domain review)VERDICT: 👍 Gittensor association: UNKNOWN; established contributor with substantial prior activity and write permission, so intent receives normal maintainer-level calibration. The advisory exception is narrowly documented and consistent with Substrate's non-WASI runtime execution. The Checks run: package/lock consistency check and FindingsNo findings. ConclusionThe PR is minimal, internally consistent, and adequately explains why the Wasmtime advisory is not reachable. No blocking domain issues found. |
|
🔄 AI review updated — Skeptic: SAFE Auditor: 👍 |
|
Folding into #3135 so the derivatives release lands as one PR off main. |
Both checks fail on `main` today; nothing in the code changes.
cargo audit
`wasmtime 8.0.1` (pinned by the polkadot-sdk fork's `sc-executor`, the same pin behind the existing wasmtime ignores) picked up RUSTSEC-2026-0269: a WASI filesystem sandbox escape via trailing slashes in paths. The runtime WASM is never given a filesystem, so the advisory is accepted next to the other wasmtime entries, with a comment. Fix upstream requires wasmtime >= 24, which comes only with a major SDK bump.
Build PR docs preview
`npm audit --audit-level=high` flags `fast-uri 3.1.5` under the Vercel CLI tree (GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp). Pinned `fast-uri` 3.1.7 through the existing `overrides` block, same pattern as the other entries there. Lockfile change is the one `fast-uri` entry.
Verified locally: `actionlint` on the workflow; `cargo audit` with the workflow's ignore list exits 0; `npm ci --ignore-scripts` then `npm audit --audit-level=high --omit=dev` report 0 vulnerabilities.
Made with Cursor