Security evidence — pg_vault_tde 1.7.2

Written by make ci-security-report (ci/scripts/run-security-report.sh), for the review of this release (doc/SECURITY-REVIEW.md). Raw logs: tmp_security/<stage>.log of the run, the artifacts of the Bitbucket custom pipeline security-report.

Commit 1cb4914a49ea10ebbcb9b1356e2d93101a2bef8e (v1.7.1-106-g1cb4914)
Working tree clean
Date 2026-09-30 04:45 UTC
Runtime podman version 4.9.3
PostgreSQL 18 (docker.io/library/postgres@sha256:4ef4dbc939d61acea57712655ddb4b4ab27419c913f94cca0cd57cb3ea3c2280)
Runtime libraries From the system, not in the SBOM. Module: OpenSSL 3 (libcrypto.so.3), libcurl (libcurl.so.4). Client tools: OpenSSL 3 (libcrypto.so.3), libcurl (libcurl.so.4), libpq (libpq.so.5). PKCS#11: the module pkcs11_library names, loaded at run time
Result PASS — every stage passed

Stages

Stage Result Counts Tool
pins PASS unpinned references 0 ci/scripts/run-pins.sh
semgrep PASS Rule tests: 7/7; Ran 7 rules on 39 files: 0 findings; nosemgrep in src/ 6 semgrep 1.178.0 (docker.io/semgrep/semgrep:1.178.0@sha256:32e459968daabe7ab86968184a29109b9564aa00392401156f9788452b42786b), rules in ci/semgrep/
sbom PASS packages 1; vulnerabilities 0; of which critical or high 0 syft-1.52.0 (docker.io/anchore/syft:v1.52.0@sha256:500e2d872ac019436926e8322b4fc1f39441d94d21f6f4046c6ff29b30e8cb02), grype-0.119.0 (docker.io/anchore/grype:v0.119.0@sha256:8c2c9234a345577a6d321a4753aa3ee1276d8975c8452d2344a56b57733ecad3), database built 2026-09-29T06:32:31Z
errorpath PASS 13 tests passed postgres (PostgreSQL) 18.6 (Debian 18.6-1.pgdg13+2), local wallet
scan-build PASS reports 0 Debian clang version 19.1.7 (3+b1)
ubsan PASS runtime errors (total) 0; naming a pg_vault_tde source 0 gcc (Debian 14.2.0-19) 14.2.0, -fsanitize=undefined
asan PASS memory errors 0 gcc (Debian 14.2.0-19) 14.2.0, -fsanitize=address, runtime preloaded
valgrind PASS Invalid free 0; Invalid read 0; Invalid write 0; Mismatched free 0; Conditional jump 0; Uninitialised value 0; definitely lost 0 valgrind-3.24.0 memcheck
cassert PASS 4 SQL files, 138 tests passed; TAP Files=48, Tests=964 PostgreSQL 18.6 from source, –enable-cassert, -DUSE_VALGRIND

The SBOM and its scan, in tmp_security/sbom/, are of the bundle make dist archives, the one the release publishes with its signed SHA256SUMS (PSQLE-180). The runtime libraries above are not in it: the release carries no copy of them, and their fixes come with the system’s updates. Vulnerability counts depend on the grype database of the day, and never fail the report.

Suppressed findings

Each line a Semgrep rule would report and that was judged right in context; the review checks every one.

  • src/kms/pg_vault_tde_rotation_bgw.c:125: /* nosemgrep: tde-caller-superuser — not SECURITY DEFINER: superuser() is the caller */
  • src/kms/pg_vault_tde_kms_local.c:2080: /* nosemgrep: tde-cleanse-before-free — cleansed in the PG_FINALLY above */
  • src/kms/pg_vault_tde_kms_local.c:2082: /* nosemgrep: tde-cleanse-before-free — cleansed in the PG_FINALLY above */
  • src/tam/pg_vault_tde_tam.c:909: /* nosemgrep: tde-rd-tableam — to be replaced by direct heapam calls, PSQLE-213 */
  • src/tam/pg_vault_tde_tam.c:1439: /* nosemgrep: tde-rd-tableam — to be replaced by direct heapam calls, PSQLE-213 */
  • src/tam/pg_vault_tde_tam.c:2824: /* nosemgrep: tde-rd-tableam — to be replaced by direct heapam calls, PSQLE-213 */

Not run here

  • CodeQL (security-extended, .github/workflows/codeql.yml): not queried (no GITHUB_TOKEN) — open alerts.
  • The functional battery: make ci-all, or the Bitbucket custom pipeline test-all.