Skip to content

CI: accept RUSTSEC-2026-0269 and patch fast-uri in the docs-preview lock - #3142

Closed
unarbos wants to merge 1 commit into
mainfrom
ci/audit-advisories
Closed

unarbos wants to merge 1 commit into
mainfrom
ci/audit-advisories

Conversation

@unarbos

@unarbos unarbos commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Both checks fail on `main` today; nothing in the code changes.

cargo audit

`wasmtime 8.0.1` (pinned by the polkadot-sdk fork's `sc-executor`, the same pin behind the existing wasmtime ignores) picked up RUSTSEC-2026-0269: a WASI filesystem sandbox escape via trailing slashes in paths. The runtime WASM is never given a filesystem, so the advisory is accepted next to the other wasmtime entries, with a comment. Fix upstream requires wasmtime >= 24, which comes only with a major SDK bump.

Build PR docs preview

`npm audit --audit-level=high` flags `fast-uri 3.1.5` under the Vercel CLI tree (GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp). Pinned `fast-uri` 3.1.7 through the existing `overrides` block, same pattern as the other entries there. Lockfile change is the one `fast-uri` entry.

Verified locally: `actionlint` on the workflow; `cargo audit` with the workflow's ignore list exits 0; `npm ci --ignore-scripts` then `npm audit --audit-level=high --omit=dev` report 0 vulnerabilities.

Made with Cursor

…ock.

cargo audit: wasmtime 8.0.1 (pinned by the polkadot-sdk fork's sc-executor,
like the other wasmtime entries) picked up RUSTSEC-2026-0269, a WASI
filesystem sandbox escape. The runtime WASM never gets a filesystem, so the
advisory is accepted alongside the existing wasmtime ignores.

docs preview: npm audit flagged fast-uri 3.1.5 (four GHSAs) under the Vercel
CLI tree. Pin fast-uri 3.1.7 via overrides; npm ci and npm audit
--audit-level=high pass locally.

Both checks have been failing on main.

Co-authored-by: Cursor <cursoragent@cursor.com>
@vercel

vercel Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
subtensor Ready Ready Preview Sep 4, 2026 12:27pm UTC

Request Review

@github-actions

github-actions Bot commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

🛡️ AI Review — Skeptic (security review)

VERDICT: SAFE

BASELINE scrutiny: established write-permission contributor with substantial merged history; no Gittensor association found; ci/audit-advisories → main.

The dependency override and matching lockfile entry narrowly upgrade fast-uri from 3.1.5 to 3.1.7. The added RustSec exception applies to a Wasmtime WASI filesystem flaw, while no WASI filesystem integration is present in the repository. No AI-review trust-boundary files are changed.

Findings

No findings.

Conclusion

The changes are consistent with the stated advisory remediation and introduce no credible security vulnerability or hostile execution path.


🔍 AI Review — Auditor (domain review)

VERDICT: 👍

Gittensor association: UNKNOWN; established contributor with substantial prior activity and write permission, so intent receives normal maintainer-level calibration.

The advisory exception is narrowly documented and consistent with Substrate's non-WASI runtime execution. The fast-uri override and lockfile entry both resolve to 3.1.7.

Checks run: package/lock consistency check and git diff --check (passed). actionlint was skipped because it is not installed in the existing environment. No build or test was needed for these CI-only changes.

Findings

No findings.

Conclusion

The PR is minimal, internally consistent, and adequately explains why the Wasmtime advisory is not reachable. No blocking domain issues found.

@github-actions

github-actions Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

🔄 AI review updated — Skeptic: SAFE Auditor: 👍

@unarbos

unarbos commented Sep 4, 2026

Copy link
Copy Markdown
Contributor Author

Folding into #3135 so the derivatives release lands as one PR off main.

@unarbos unarbos closed this Sep 4, 2026
@unarbos
unarbos deleted the ci/audit-advisories branch September 4, 2026 12:47

This branch was successfully deployed

1 active deployment
Preview — 01fe7b09 Deployed Sep 4, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant