Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 27 additions & 0 deletions .secrets-audit-justifications.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
# `.secrets.baseline` Audit Justifications

The `detect-secrets` pre-commit hook runs with `--baseline .secrets.baseline`
(see `.pre-commit-config.yaml`). The baseline is generated from a scan of all
tracked files and every finding below has been manually reviewed and marked
`"is_secret": false` with the justification recorded here.

## Baselined findings

| File | Line | Type | Justification |
| --- | --- | --- | --- |
| `docker-compose.yml` | 42 | Secret Keyword | Local-only dev Postgres password (`propchain123`) for the `propchain-postgres` container. Port is bound to localhost; never used in staging/production. |
| `docker-compose.yml` | 68 | Basic Auth Credentials | `DATABASE_URL` embedding the same local-only dev credential (`propchain:propchain123@postgres`) for the indexer container. |
| `scripts/archive-events.sh` | 9 | Basic Auth Credentials | Usage docstring template `postgres://user:pass@host:5432/db`. Literal placeholder, not a credential. |
| `scripts/test_accounts.rs` | 8-10 | Base64 High Entropy String | Well-known public Substrate/ink test account addresses (Alice/Bob/Charlie `5Grw...`, `5FHne...`, `5FLSi...`). Public keys, not private keys or seeds. |

## Baseline workflow

- **Regenerate** after adding files or plugins:
`detect-secrets scan $(git ls-files) > .secrets.baseline`
- **Audit new findings** and mark them `is_secret: true/false` with:
`detect-secrets audit .secrets.baseline` (interactive) or
`detect-secrets audit --report .secrets.baseline` (summary).
- **Record justification** for every `is_secret: false` finding in the table
above.
- The hook passes when `pre-commit run detect-secrets` reports no findings that
are both outside the baseline and not marked audited.
167 changes: 167 additions & 0 deletions .secrets.baseline

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

24 changes: 24 additions & 0 deletions AUDIT_LOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -491,3 +491,27 @@ workspace: /home/runner/work/PropChain-contract/PropChain-contract/Cargo.toml
| ^

error: could not compile `propchain-bridge` (lib test) due to 1 previous error

---

## ✅ Advisory Triage — h2 / rustls-webpki (issue #1203, 2026-09-29)

`cargo-audit` flags 8 advisories against transitive dependencies pinned by the
substrate/ink toolchain. They are now explicitly ignored with justification in
`audit.toml` so that remaining *new* advisories fail the audit gate:

| Advisory | Crate (pinned version) | Action & justification |
| --- | --- | --- |
| RUSTSEC-2026-0258 | h2 0.3.27 | Ignored. Upgrade path (h2 >= 0.4.16) requires a hyper/tokio stack bump out of scope for ink! 5.1. No workspace code path exposes the vulnerable HTTP/2 empty-DATA-frame handling; contracts never terminate HTTP/2. |
| RUSTSEC-2026-0098 | rustls-webpki 0.101.7 / 0.102.8 | Ignored. Fix line (0.103.x) requires a rustls major bump. Workspace has no rustls client parsing untrusted certificates. |
| RUSTSEC-2026-0104 | rustls-webpki 0.101.7 / 0.102.8 | Already ignored (pre-existing entry, unchanged). |
| RUSTSEC-2026-0002 | lru 0.12.5 | Already ignored (pre-existing entry, unchanged). |

Each ignore entry in `audit.toml` carries a comment with the justification and
a re-evaluation note for the next toolchain upgrade. `cargo-deny check` must be
re-run in CI to confirm zero unignored advisories (deny.toml license-key
cleanup is tracked separately and out of scope here).

Secrets scanning (issue #1211): `.secrets.baseline` committed; audited
findings and the baseline workflow are documented in
`.secrets-audit-justifications.md`.
15 changes: 14 additions & 1 deletion audit.toml
Original file line number Diff line number Diff line change
@@ -1,2 +1,15 @@
[advisories]
ignore = ["RUSTSEC-2026-0104", "RUSTSEC-2026-0002"]
# h2 0.3.27 (RUSTSEC-2026-0258, unbounded empty DATA frames).
# Pinned transitively by the substrate/ink toolchain; h2 >= 0.4 needs a
# hyper/tokio stack bump that is out of scope for the ink! 5.1 workspace.
# No workspace code path exposes the vulnerable HTTP/2 DATA-frame handling.
# Re-evaluate on the next toolchain upgrade. Tracked in issue #1203.
"RUSTSEC-2026-0258",
# rustls-webpki 0.101.7/0.102.8 (RUSTSEC-2026-0098, URI name constraints
# incorrectly accepted). Pinned transitively by the substrate/ink toolchain;
# 0.103.x requires a rustls major bump. No rustls client in this workspace
# parses untrusted certificates. Re-evaluate on the next toolchain upgrade.
# Tracked in issue #1203.
"RUSTSEC-2026-0098",
"RUSTSEC-2026-0104",
"RUSTSEC-2026-0002"]
Loading