adorsys / adorsys/status-list-server
[SECURITY] Pin Rust toolchain, commit Cargo.lock, and adopt cargo vet for supply chain reproducibility
- Linguagem predominante
- Rust
- Estrelas
- 22
- Forks
- 5
- Merge médio
- 2d 6h
- PRs com merge (30d)
- 47
Descrição
## Problem
Our Rust project does not pin the compiler version (no `rust-toolchain.toml`) and does not refresh/lock the dependency set on a cadence. This means:
- Builds are non-reproducible across environments
- Transitive dependency upgrades happen silently
- We cannot audit exactly what code was compiled into production binaries
## Risk
- A malicious or vulnerable crate version could enter the build undetected
- We cannot respond quickly to a supply chain incident (e.g. RustSec advisory)
- Fails SOC2 / internal security audit reproducibility requirements
## Proposed Fix
1. Add `rust-toolchain.toml` pinned to the approved version (`1.96.0`, the version currently in use).
2. Commit `Cargo.lock` to the repo (already tracked) and refresh it with `cargo update` so the lockfile reflects a known-good, audited dependency set.
3. Add `cargo audit` + `cargo deny` to the CI pipeline (already present via `.github/workflows/cargo_deny.yml`, wired into `CI.yml`).
4. Adopt `cargo vet` for supply chain sign-off (initialize `supply-chain/` and run `cargo vet` in CI).
## References
- Mirrors [adorsys/didcomm-mediator-rs#450](https://github.com/adorsys/didcomm-mediator-rs/issues/450)
- Related: #138 (production readiness — supply-chain security), #142 (CI hardening), #163 (CI workflow PR)
Guia de contribuição
Direção de pesquisa
Start in `.github/workflows/CI.yml` and `.github/workflows/cargo_deny.yml` to verify current security gating, then inspect repository root files like `Cargo.lock` and whether `rust-toolchain.toml` already exists elsewhere. Run `cargo update` to regenerate a known set, review `supply-chain/` expectations from related CI context, and prepare to add `cargo audit`, `cargo deny`, and `cargo vet` steps. Done means Rust toolchain is pinned to 1.96.0, `Cargo.lock` is committed and stable, and CI passes with all checks running.
Escrita pelo modelo de indexação a partir do texto da issue.
Avaliação
- Stack de tecnologia
- github-actions, rust
- Domínio
- ci-cd, security
- Tipo de issue
- Funcionalidade
- Dificuldade
- 3/5
- Tempo estimado
- 1-2 dias
- Status de atividade
- Pouca atividade
- Clareza
- Razoavelmente clara
- Facilidade para iniciantes
- 67/100