fix(cloudfront): serve DefaultRootObject at the distribution root #2
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Security Audit | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| env: | |
| CARGO_TERM_COLOR: always | |
| jobs: | |
| changes: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| outputs: | |
| code: ${{ steps.detect.outputs.code || 'true' }} | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| - if: github.event_name == 'pull_request' | |
| id: detect | |
| uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4.0.1 | |
| with: | |
| predicate-quantifier: 'every' | |
| filters: | | |
| code: | |
| - '**' | |
| - '!**/*.md' | |
| - '!**/*.txt' | |
| - '!**/*.html' | |
| - '!docs/**' | |
| - '!website/**' | |
| - '!LICENSE' | |
| - '!.gitignore' | |
| audit: | |
| needs: changes | |
| if: needs.changes.outputs.code == 'true' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable | |
| - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 | |
| - name: Install cargo-audit | |
| run: | | |
| for i in 1 2 3; do | |
| cargo install cargo-audit && ok=1 && break | |
| echo "cargo install cargo-audit attempt $i failed; retrying"; sleep $((i * 5)) | |
| done | |
| [ "${ok:-}" = 1 ] || { echo "cargo install cargo-audit failed after 3 attempts"; exit 1; } | |
| # RUSTSEC-2026-0098/0099/0104 (rustls-webpki 0.101.x) reach us only | |
| # through rustls 0.21 -> aws-smithy-http-client. Our own rustls-webpki | |
| # 0.103.x is already on the patched release (0.103.13+); we can't drop | |
| # the 0.101 pull chain until the AWS Rust SDK moves off rustls 0.21. | |
| # | |
| # RUSTSEC-2026-0002 (lru 0.12.5 IterMut Stacked Borrows) is pulled in | |
| # transitively by aws-sdk-s3 and mysql_async. We never construct or | |
| # iterate those crates' internal LRU instances, so the unsoundness is | |
| # unreachable from our code. | |
| # | |
| # RUSTSEC-2026-0097 (rand 0.8.5 unsound with custom logger) reaches us | |
| # via mysql_async / twox-hash / rust_decimal / mysql_common. The advisory | |
| # requires a user-installed custom logger that calls `rand::rng()` during | |
| # logging — fakecloud does not install such a logger. | |
| # | |
| # RUSTSEC-2023-0071 (rsa 0.9 Marvin Attack timing sidechannel) reaches us | |
| # only through fakecloud-sns's RSA-SHA256 signing key — generated once | |
| # per process for SNS message signatures consumers verify in tests. The | |
| # attack requires a remote oracle that times decryption operations on a | |
| # private key handling attacker-chosen ciphertexts. fakecloud's signing | |
| # key is never used for decrypt and never handles attacker-chosen input; | |
| # there is no fixed upgrade path because rsa upstream has not released a | |
| # constant-time fix yet. The same advisory is the standard escape hatch | |
| # for any project that needs RSA in pure Rust today. | |
| # | |
| # RUSTSEC-2026-0185 (backoff is unmaintained) reaches us only transitively | |
| # through kube-runtime's retry/backoff timers. It is an unmaintained-crate | |
| # advisory, not an exploitable vulnerability; backoff computes retry delays | |
| # and handles no untrusted input. No action until kube drops the dependency. | |
| # | |
| # RUSTSEC-2026-0194 / RUSTSEC-2026-0195 (quick-xml <0.41: quadratic | |
| # duplicate-attribute check + unbounded namespace-declaration allocation) | |
| # are algorithmic-complexity / memory DoS reachable only by feeding the | |
| # parser adversarial XML. quick-xml is pinned at 0.37 workspace-wide for the | |
| # S3 / RDS / ELBv2 / Route53 REST-XML (de)serializers, which parse the | |
| # emulator's own responses and trusted local test inputs, not attacker- | |
| # controlled documents. The fix requires jumping to quick-xml >=0.41, a | |
| # breaking API change across every XML service; tracked as a dedicated | |
| # upgrade rather than blocking every PR on a low-exposure DoS advisory. | |
| # | |
| # The advisories below are unmaintained / unsound / yanked warnings on | |
| # transitive dependencies that handle no attacker-controlled input in | |
| # fakecloud. They surfaced as the RustSec DB drifted and now redden every | |
| # PR and main until an upstream fix lands; ignored with the same policy as | |
| # the entries above. | |
| # | |
| # RUSTSEC-2024-0384 (paste), RUSTSEC-2024-0436 (proc-macro-error2) and | |
| # RUSTSEC-2025-0012 (derivative) are unmaintained proc-macro / derive | |
| # helpers used only at build time; they never touch runtime input. | |
| # | |
| # RUSTSEC-2024-0388 (instant) and RUSTSEC-2026-0235 (backoff) are | |
| # unmaintained crates reached transitively through the async / kube retry | |
| # stack (same reachability as RUSTSEC-2026-0185 above): timers and delay | |
| # math over no untrusted input. | |
| # | |
| # RUSTSEC-2026-0173 (rustls-pemfile unmaintained) parses only the | |
| # emulator's own trusted PEM material, never attacker-supplied files. | |
| # | |
| # RUSTSEC-2025-0134 (anyhow Error::downcast_mut unsoundness) and | |
| # RUSTSEC-2026-0190 (event-listener !Send StackSlot unsoundness) reach us | |
| # transitively; fakecloud does not exercise the unsound APIs (we never call | |
| # anyhow's downcast_mut, nor cross a thread boundary with a !Send listener | |
| # tag) and neither advisory has a fixed release on our pinned versions yet. | |
| # | |
| # RUSTSEC-2026-0221 (spin 0.9.8 yanked) is a yanked transitive spinlock | |
| # dependency; nothing in fakecloud's tree can move off it until upstream | |
| # crates republish. | |
| # | |
| # RUSTSEC-2026-0258 (h2 unbounded empty DATA frames) is fixed on the 0.4 | |
| # line (bumped to 0.4.16) but still reaches us via the legacy h2 0.3.x that | |
| # hyper 0.14 pulls in transitively; the 0.3 line has no patched release, so | |
| # that one path stays ignored until the upstream 0.14 stack moves off it. | |
| - run: | | |
| cargo audit \ | |
| --ignore RUSTSEC-2026-0098 \ | |
| --ignore RUSTSEC-2026-0099 \ | |
| --ignore RUSTSEC-2026-0104 \ | |
| --ignore RUSTSEC-2026-0002 \ | |
| --ignore RUSTSEC-2026-0097 \ | |
| --ignore RUSTSEC-2023-0071 \ | |
| --ignore RUSTSEC-2026-0185 \ | |
| --ignore RUSTSEC-2026-0194 \ | |
| --ignore RUSTSEC-2026-0195 \ | |
| --ignore RUSTSEC-2024-0384 \ | |
| --ignore RUSTSEC-2024-0388 \ | |
| --ignore RUSTSEC-2024-0436 \ | |
| --ignore RUSTSEC-2025-0012 \ | |
| --ignore RUSTSEC-2025-0134 \ | |
| --ignore RUSTSEC-2026-0173 \ | |
| --ignore RUSTSEC-2026-0190 \ | |
| --ignore RUSTSEC-2026-0221 \ | |
| --ignore RUSTSEC-2026-0235 \ | |
| --ignore RUSTSEC-2026-0258 |