Skip to content

fix(cloudfront): serve DefaultRootObject at the distribution root #2

fix(cloudfront): serve DefaultRootObject at the distribution root

fix(cloudfront): serve DefaultRootObject at the distribution root #2

Workflow file for this run

name: Security Audit
on:
push:
branches: [main]
pull_request:
branches: [main]
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
env:
CARGO_TERM_COLOR: always
jobs:
changes:
runs-on: ubuntu-latest
timeout-minutes: 30
outputs:
code: ${{ steps.detect.outputs.code || 'true' }}
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- if: github.event_name == 'pull_request'
id: detect
uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4.0.1
with:
predicate-quantifier: 'every'
filters: |
code:
- '**'
- '!**/*.md'
- '!**/*.txt'
- '!**/*.html'
- '!docs/**'
- '!website/**'
- '!LICENSE'
- '!.gitignore'
audit:
needs: changes
if: needs.changes.outputs.code == 'true'
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
- name: Install cargo-audit
run: |
for i in 1 2 3; do
cargo install cargo-audit && ok=1 && break
echo "cargo install cargo-audit attempt $i failed; retrying"; sleep $((i * 5))
done
[ "${ok:-}" = 1 ] || { echo "cargo install cargo-audit failed after 3 attempts"; exit 1; }
# RUSTSEC-2026-0098/0099/0104 (rustls-webpki 0.101.x) reach us only
# through rustls 0.21 -> aws-smithy-http-client. Our own rustls-webpki
# 0.103.x is already on the patched release (0.103.13+); we can't drop
# the 0.101 pull chain until the AWS Rust SDK moves off rustls 0.21.
#
# RUSTSEC-2026-0002 (lru 0.12.5 IterMut Stacked Borrows) is pulled in
# transitively by aws-sdk-s3 and mysql_async. We never construct or
# iterate those crates' internal LRU instances, so the unsoundness is
# unreachable from our code.
#
# RUSTSEC-2026-0097 (rand 0.8.5 unsound with custom logger) reaches us
# via mysql_async / twox-hash / rust_decimal / mysql_common. The advisory
# requires a user-installed custom logger that calls `rand::rng()` during
# logging — fakecloud does not install such a logger.
#
# RUSTSEC-2023-0071 (rsa 0.9 Marvin Attack timing sidechannel) reaches us
# only through fakecloud-sns's RSA-SHA256 signing key — generated once
# per process for SNS message signatures consumers verify in tests. The
# attack requires a remote oracle that times decryption operations on a
# private key handling attacker-chosen ciphertexts. fakecloud's signing
# key is never used for decrypt and never handles attacker-chosen input;
# there is no fixed upgrade path because rsa upstream has not released a
# constant-time fix yet. The same advisory is the standard escape hatch
# for any project that needs RSA in pure Rust today.
#
# RUSTSEC-2026-0185 (backoff is unmaintained) reaches us only transitively
# through kube-runtime's retry/backoff timers. It is an unmaintained-crate
# advisory, not an exploitable vulnerability; backoff computes retry delays
# and handles no untrusted input. No action until kube drops the dependency.
#
# RUSTSEC-2026-0194 / RUSTSEC-2026-0195 (quick-xml <0.41: quadratic
# duplicate-attribute check + unbounded namespace-declaration allocation)
# are algorithmic-complexity / memory DoS reachable only by feeding the
# parser adversarial XML. quick-xml is pinned at 0.37 workspace-wide for the
# S3 / RDS / ELBv2 / Route53 REST-XML (de)serializers, which parse the
# emulator's own responses and trusted local test inputs, not attacker-
# controlled documents. The fix requires jumping to quick-xml >=0.41, a
# breaking API change across every XML service; tracked as a dedicated
# upgrade rather than blocking every PR on a low-exposure DoS advisory.
#
# The advisories below are unmaintained / unsound / yanked warnings on
# transitive dependencies that handle no attacker-controlled input in
# fakecloud. They surfaced as the RustSec DB drifted and now redden every
# PR and main until an upstream fix lands; ignored with the same policy as
# the entries above.
#
# RUSTSEC-2024-0384 (paste), RUSTSEC-2024-0436 (proc-macro-error2) and
# RUSTSEC-2025-0012 (derivative) are unmaintained proc-macro / derive
# helpers used only at build time; they never touch runtime input.
#
# RUSTSEC-2024-0388 (instant) and RUSTSEC-2026-0235 (backoff) are
# unmaintained crates reached transitively through the async / kube retry
# stack (same reachability as RUSTSEC-2026-0185 above): timers and delay
# math over no untrusted input.
#
# RUSTSEC-2026-0173 (rustls-pemfile unmaintained) parses only the
# emulator's own trusted PEM material, never attacker-supplied files.
#
# RUSTSEC-2025-0134 (anyhow Error::downcast_mut unsoundness) and
# RUSTSEC-2026-0190 (event-listener !Send StackSlot unsoundness) reach us
# transitively; fakecloud does not exercise the unsound APIs (we never call
# anyhow's downcast_mut, nor cross a thread boundary with a !Send listener
# tag) and neither advisory has a fixed release on our pinned versions yet.
#
# RUSTSEC-2026-0221 (spin 0.9.8 yanked) is a yanked transitive spinlock
# dependency; nothing in fakecloud's tree can move off it until upstream
# crates republish.
#
# RUSTSEC-2026-0258 (h2 unbounded empty DATA frames) is fixed on the 0.4
# line (bumped to 0.4.16) but still reaches us via the legacy h2 0.3.x that
# hyper 0.14 pulls in transitively; the 0.3 line has no patched release, so
# that one path stays ignored until the upstream 0.14 stack moves off it.
- run: |
cargo audit \
--ignore RUSTSEC-2026-0098 \
--ignore RUSTSEC-2026-0099 \
--ignore RUSTSEC-2026-0104 \
--ignore RUSTSEC-2026-0002 \
--ignore RUSTSEC-2026-0097 \
--ignore RUSTSEC-2023-0071 \
--ignore RUSTSEC-2026-0185 \
--ignore RUSTSEC-2026-0194 \
--ignore RUSTSEC-2026-0195 \
--ignore RUSTSEC-2024-0384 \
--ignore RUSTSEC-2024-0388 \
--ignore RUSTSEC-2024-0436 \
--ignore RUSTSEC-2025-0012 \
--ignore RUSTSEC-2025-0134 \
--ignore RUSTSEC-2026-0173 \
--ignore RUSTSEC-2026-0190 \
--ignore RUSTSEC-2026-0221 \
--ignore RUSTSEC-2026-0235 \
--ignore RUSTSEC-2026-0258