Security evidence — pg_vault_tde 1.7.2
Written by make ci-security-report (ci/scripts/run-security-report.sh), for the
review of this release (doc/SECURITY-REVIEW.md).
Raw logs: tmp_security/<stage>.log of the run, the artifacts of the Bitbucket
custom pipeline security-report.
| Commit | 1cb4914a49ea10ebbcb9b1356e2d93101a2bef8e (v1.7.1-106-g1cb4914) |
| Working tree | clean |
| Date | 2026-09-30 04:45 UTC |
| Runtime | podman version 4.9.3 |
| PostgreSQL | 18 (docker.io/library/postgres@sha256:4ef4dbc939d61acea57712655ddb4b4ab27419c913f94cca0cd57cb3ea3c2280) |
| Runtime libraries | From the system, not in the SBOM. Module: OpenSSL 3 (libcrypto.so.3), libcurl (libcurl.so.4). Client tools: OpenSSL 3 (libcrypto.so.3), libcurl (libcurl.so.4), libpq (libpq.so.5). PKCS#11: the module pkcs11_library names, loaded at run time |
| Result | PASS — every stage passed |
Stages
| Stage | Result | Counts | Tool |
|---|---|---|---|
pins |
PASS | unpinned references 0 | ci/scripts/run-pins.sh |
semgrep |
PASS | Rule tests: 7/7; Ran 7 rules on 39 files: 0 findings; nosemgrep in src/ 6 | semgrep 1.178.0 (docker.io/semgrep/semgrep:1.178.0@sha256:32e459968daabe7ab86968184a29109b9564aa00392401156f9788452b42786b), rules in ci/semgrep/ |
sbom |
PASS | packages 1; vulnerabilities 0; of which critical or high 0 | syft-1.52.0 (docker.io/anchore/syft:v1.52.0@sha256:500e2d872ac019436926e8322b4fc1f39441d94d21f6f4046c6ff29b30e8cb02), grype-0.119.0 (docker.io/anchore/grype:v0.119.0@sha256:8c2c9234a345577a6d321a4753aa3ee1276d8975c8452d2344a56b57733ecad3), database built 2026-09-29T06:32:31Z |
errorpath |
PASS | 13 tests passed | postgres (PostgreSQL) 18.6 (Debian 18.6-1.pgdg13+2), local wallet |
scan-build |
PASS | reports 0 | Debian clang version 19.1.7 (3+b1) |
ubsan |
PASS | runtime errors (total) 0; naming a pg_vault_tde source 0 | gcc (Debian 14.2.0-19) 14.2.0, -fsanitize=undefined |
asan |
PASS | memory errors 0 | gcc (Debian 14.2.0-19) 14.2.0, -fsanitize=address, runtime preloaded |
valgrind |
PASS | Invalid free 0; Invalid read 0; Invalid write 0; Mismatched free 0; Conditional jump 0; Uninitialised value 0; definitely lost 0 | valgrind-3.24.0 memcheck |
cassert |
PASS | 4 SQL files, 138 tests passed; TAP Files=48, Tests=964 | PostgreSQL 18.6 from source, –enable-cassert, -DUSE_VALGRIND |
The SBOM and its scan, in tmp_security/sbom/, are of the bundle make dist archives,
the one the release publishes with its signed SHA256SUMS (PSQLE-180). The runtime
libraries above are not in it: the release carries no copy of them, and their fixes
come with the system’s updates. Vulnerability counts depend on the grype database of
the day, and never fail the report.
Suppressed findings
Each line a Semgrep rule would report and that was judged right in context; the review checks every one.
src/kms/pg_vault_tde_rotation_bgw.c:125:/* nosemgrep: tde-caller-superuser — not SECURITY DEFINER: superuser() is the caller */src/kms/pg_vault_tde_kms_local.c:2080:/* nosemgrep: tde-cleanse-before-free — cleansed in the PG_FINALLY above */src/kms/pg_vault_tde_kms_local.c:2082:/* nosemgrep: tde-cleanse-before-free — cleansed in the PG_FINALLY above */src/tam/pg_vault_tde_tam.c:909:/* nosemgrep: tde-rd-tableam — to be replaced by direct heapam calls, PSQLE-213 */src/tam/pg_vault_tde_tam.c:1439:/* nosemgrep: tde-rd-tableam — to be replaced by direct heapam calls, PSQLE-213 */src/tam/pg_vault_tde_tam.c:2824:/* nosemgrep: tde-rd-tableam — to be replaced by direct heapam calls, PSQLE-213 */
Not run here
- CodeQL (
security-extended,.github/workflows/codeql.yml): not queried (no GITHUB_TOKEN) — open alerts. - The functional battery:
make ci-all, or the Bitbucket custom pipelinetest-all.