Skip to content

hardening: 3 latent Hypatia findings (unsafe SAFETY comments, setup-deno SHA-pin, secret presence-gate) #655

Description

@hyperpolymath

Context

Surfaced by the Hypatia security-scan comment on PR #651 (a docs-only PR). Per .claude/CLAUDE.md, that comment reports findings across the whole repo and is treated as noise unless a finding is a delta in the PR's changed files — none of these are; they are pre-existing and outside #651's changeset (NAVIGATION.adoc, tutorial/lesson-01-hello.adoc, STATE.a2ml). Filing here so the genuine ones are tracked rather than lost in the recurring scan output. The gating Hypatia check-run is separate and unaffected.

Items

  • unsafe blocks missing SAFETY: comments (CWE-676): runtime/src/panic.rs (2), runtime/src/alloc.rs (1), runtime/src/ffi.rs (3). Add a // SAFETY: justification to each.
  • denoland/setup-deno@v2 unpinned in .github/workflows/publish-jsr.yml — pin to a full commit SHA, per the repo's "pin every uses: to a SHA" rule (also avoids the tag-pinned-ref startup_failure class).
  • secret_action_without_presence_gate (high) in .github/workflows/instant-sync.yml — gate the peter-evans/repository-dispatch step on presence of its secret.

Explicitly NOT in scope (documented exemptions / accepted)

  • packages/affinescript-cli/mod.js js_exec_sync — approved Runtime Exemption (distribution-shim node:child_process); see CLAUDE.md.
  • packages/affine-vscode/mod.js, affinescript-vite/src/affine-plugin-improved.js js_exec_sync — JS carve-outs / tooling shims.
  • expect_in_hot_path in affinescriptiser/src/codegen/{wasm_gen,affine_gen}.rsexpect() with messages in codegen is acceptable; lower priority, can revisit separately.

Follow-up

The scan reported 2 "critical" findings not enumerated in the comment's truncated JSON. Confirming/triaging those needs the full Hypatia finding set — separate task; can be pulled on request.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    automationBots, schedulers, dispatch, self-healing, fan-outchoreRoutine maintenance with no behaviour changemigrationPorting between languages or toolchains (e.g. -> AffineScript)security

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions