Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 8 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,12 +21,12 @@ on:
type: string
required: false
default: ""
description: "Tag to re-publish (existing tag). Omit + set from-head to release HEAD."
description: "Tag to publish (e.g. v1.14.5)"
from-head:
type: string
required: false
default: ""
description: "'true' to release/retry the current HEAD (issue #35)."
description: "'true' to release/retry the current HEAD."
bump:
type: string
required: false
Expand All @@ -42,6 +42,11 @@ on:
required: false
default: ""
description: "'true' to consent, for this run only, to shipping a skipped-optimisation build under a release tag."
optimize-tier:
type: string
required: false
default: ""
description: "'release' to build the release optimisation tier on a run that publishes nothing (Rust: PGO + BOLT)."

permissions:
contents: write
Expand All @@ -58,6 +63,7 @@ jobs:
bump: ${{ inputs.bump || 'auto' }}
skip-optimize: ${{ inputs.skip-optimize || '' }}
release-unoptimized: ${{ inputs.release-unoptimized || '' }}
optimize-tier: ${{ inputs.optimize-tier || '' }}
# Least privilege: pass only the secrets rust-ci.yml consumes, never `inherit`.
secrets:
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
Expand Down
15 changes: 8 additions & 7 deletions .hyperi-ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,15 +22,16 @@ quality:
# GHSA-w9wp-h8wv-79jx / CVE-2026-48504: opentelemetry_sdk 0.31.0 is in the
# lock through scalo, in the affected range (<= 0.32.0, fixed in 0.32.1).
# The flaw is in BaggagePropagator::extract_with_context, which parses an
# inbound W3C Baggage header before enforcing its size limits. Nothing here
# reaches it: neither dfe-loader nor scalo names `baggage`, and neither
# installs a text map propagator, so the function is never called. It is a
# GitHub advisory with no RustSec entry, so only osv-scanner sees it and
# deny.toml needs no matching ignore. Drop this when scalo lifts its
# opentelemetry_sdk pin to >= 0.32.1 (scalo-rs#34, scalo-rs#100).
# inbound W3C Baggage header before enforcing its size limits. It is
# unreachable: no Baggage propagator is registered in dfe-loader or in scalo,
# so the function is never called. Accepted as not reachable in dfe-infra
# docs/THREAT-MODEL.md, accepted risks. scalo cannot move to 0.32 while
# metrics-exporter-opentelemetry 0.2.1 requires opentelemetry ^0.31;
# hyperi-io/scalo-rs#281 tracks the move. A GitHub advisory with no RustSec
# entry, so only osv-scanner sees it and deny.toml needs no matching ignore.
- tool: osv-scanner
id: GHSA-w9wp-h8wv-79jx
reason: "CVE-2026-48504, opentelemetry_sdk 0.31.0 via scalo: BaggagePropagator::extract_with_context is unreachable (no text map propagator, no baggage in dfe-loader or scalo). Drop when scalo allows opentelemetry_sdk >= 0.32.1 (scalo-rs#34/#100)."
reason: "CVE-2026-48504, opentelemetry_sdk 0.31.0 via scalo: unreachable, no Baggage propagator is registered in dfe-loader or scalo. Accepted risk in dfe-infra docs/THREAT-MODEL.md. Blocked on metrics-exporter-opentelemetry 0.2.1 requiring opentelemetry ^0.31; tracked in hyperi-io/scalo-rs#281."
# Rust: test specific feature sets (avoids --all-features conflicts).
# DFE policy 2026-04-17 — jemalloc only; mimalloc removed.
rust:
Expand Down
Loading
Loading