Skip to content

fix: add detect-secrets baseline and triage cargo-audit advisories - #1246

Merged
nanaf6203-bit merged 1 commit into
MettaChain:mainfrom
DanielCharis1:fix/issues-1203-1211-secrets-baseline-audit
Sep 30, 2026
Merged

nanaf6203-bit merged 1 commit into
MettaChain:mainfrom
DanielCharis1:fix/issues-1203-1211-secrets-baseline-audit

Conversation

@DanielCharis1

@DanielCharis1 DanielCharis1 commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Resolves the two issues assigned to @DanielCharis1 with a single, low-risk change:

#1211 — missing .secrets.baseline breaks the detect-secrets hook

  • Adds a committed .secrets.baseline (generated with detect-secrets v1.4.0, matching the hook rev) so pre-commit run detect-secrets passes deterministically instead of erroring / running un-baselined.
  • All 6 findings from the full tracked-file scan were manually audited and marked is_secret: false — they are false positives:
    • docker-compose.yml (lines 42, 68): local-only dev Postgres credential (propchain123)
    • scripts/archive-events.sh (line 9): usage-docstring placeholder postgres://user:pass@host
    • scripts/test_accounts.rs (lines 8–10): well-known public Substrate Alice/Bob/Charlie addresses (public keys, not seeds)
  • Justifications + baseline maintenance workflow documented in .secrets-audit-justifications.md.

#1203 — cargo-audit advisories h2 0.3.27 / rustls-webpki 0.101.7

Per the issue's proposed approach ("pin older transitive versions deliberately with audit.toml ignore with justification"):

  • audit.toml now explicitly ignores RUSTSEC-2026-0258 (h2 0.3.27) and RUSTSEC-2026-0098 (rustls-webpki 0.101.7/0.102.8), each with an inline justification: both are pinned transitively by the substrate/ink toolchain; the fixed versions require a hyper/rustls major bump out of scope for the ink! 5.1 workspace, and no workspace code path exposes the vulnerable surfaces (no HTTP/2 termination, no rustls client parsing untrusted certs). Re-evaluation notes included.
  • Triage table recorded in AUDIT_LOG.md; pre-existing ignores (RUSTSEC-2026-0104, RUSTSEC-2026-0002) unchanged.

Test plan

  • Baseline regenerated from git ls-files with the hook's detect-secrets version and audited
  • audit.toml / .secrets.baseline TOML+JSON validity
  • CI: nightly cargo audit / cargo-deny check should report zero unignored advisories (deny.toml license-key cleanup is tracked separately and intentionally out of scope)

Closes #1211
Closes #1203

…ettaChain#1211, MettaChain#1203)

Commit a committed .secrets.baseline so the pre-commit detect-secrets hook
passes deterministically: findings from a full tracked-file scan were audited
(6 false positives: dev-only compose credentials, a usage placeholder and
public Substrate test addresses) and documented in
.secrets-audit-justifications.md together with the baseline workflow.

Ignore the pinned-transitive h2 (RUSTSEC-2026-0258) and rustls-webpki
(RUSTSEC-2026-0098) advisories in audit.toml with per-entry justification,
per the approach accepted in the issue, and record the triage in AUDIT_LOG.md.

Closes MettaChain#1211
Closes MettaChain#1203

🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
@drips-wave

drips-wave Bot commented Sep 29, 2026

Copy link
Copy Markdown

@DanielCharis1 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@nanaf6203-bit nanaf6203-bit left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@nanaf6203-bit
nanaf6203-bit merged commit bc3ce2e into MettaChain:main Sep 30, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants