# Security evidence — pg_vault_tde 1.7.2 Written by `make ci-security-report` (`ci/scripts/run-security-report.sh`), for the review of this release ([doc/SECURITY-REVIEW.md](../../SECURITY-REVIEW.md#workflow)). Raw logs: `tmp_security/.log` of the run, the artifacts of the Bitbucket custom pipeline `security-report`. | | | |---|---| | Commit | `1cb4914a49ea10ebbcb9b1356e2d93101a2bef8e` (`v1.7.1-106-g1cb4914`) | | Working tree | clean | | Date | 2026-09-30 04:45 UTC | | Runtime | podman version 4.9.3 | | PostgreSQL | 18 (`docker.io/library/postgres@sha256:4ef4dbc939d61acea57712655ddb4b4ab27419c913f94cca0cd57cb3ea3c2280`) | | Runtime libraries | From the system, not in the SBOM. Module: OpenSSL 3 (`libcrypto.so.3`), libcurl (`libcurl.so.4`). Client tools: OpenSSL 3 (`libcrypto.so.3`), libcurl (`libcurl.so.4`), libpq (`libpq.so.5`). PKCS#11: the module `pkcs11_library` names, loaded at run time | | Result | **PASS** — every stage passed | ## Stages | Stage | Result | Counts | Tool | |---|---|---|---| | `pins` | PASS | unpinned references 0 | ci/scripts/run-pins.sh | | `semgrep` | PASS | Rule tests: 7/7; Ran 7 rules on 39 files: 0 findings; nosemgrep in src/ 6 | semgrep 1.178.0 (`docker.io/semgrep/semgrep:1.178.0@sha256:32e459968daabe7ab86968184a29109b9564aa00392401156f9788452b42786b`), rules in `ci/semgrep/` | | `sbom` | PASS | packages 1; vulnerabilities 0; of which critical or high 0 | syft-1.52.0 (`docker.io/anchore/syft:v1.52.0@sha256:500e2d872ac019436926e8322b4fc1f39441d94d21f6f4046c6ff29b30e8cb02`), grype-0.119.0 (`docker.io/anchore/grype:v0.119.0@sha256:8c2c9234a345577a6d321a4753aa3ee1276d8975c8452d2344a56b57733ecad3`), database built 2026-09-29T06:32:31Z | | `errorpath` | PASS | 13 tests passed | postgres (PostgreSQL) 18.6 (Debian 18.6-1.pgdg13+2), local wallet | | `scan-build` | PASS | reports 0 | Debian clang version 19.1.7 (3+b1) | | `ubsan` | PASS | runtime errors (total) 0; naming a pg_vault_tde source 0 | gcc (Debian 14.2.0-19) 14.2.0, -fsanitize=undefined | | `asan` | PASS | memory errors 0 | gcc (Debian 14.2.0-19) 14.2.0, -fsanitize=address, runtime preloaded | | `valgrind` | PASS | Invalid free 0; Invalid read 0; Invalid write 0; Mismatched free 0; Conditional jump 0; Uninitialised value 0; definitely lost 0 | valgrind-3.24.0 memcheck | | `cassert` | PASS | 4 SQL files, 138 tests passed; TAP Files=48, Tests=964 | PostgreSQL 18.6 from source, --enable-cassert, -DUSE_VALGRIND | The SBOM and its scan, in `tmp_security/sbom/`, are of the bundle `make dist` archives, the one the release publishes with its signed `SHA256SUMS` (PSQLE-180). The runtime libraries above are not in it: the release carries no copy of them, and their fixes come with the system's updates. Vulnerability counts depend on the grype database of the day, and never fail the report. ## Suppressed findings Each line a Semgrep rule would report and that was judged right in context; the review checks every one. - `src/kms/pg_vault_tde_rotation_bgw.c:125`: `/* nosemgrep: tde-caller-superuser — not SECURITY DEFINER: superuser() is the caller */` - `src/kms/pg_vault_tde_kms_local.c:2080`: `/* nosemgrep: tde-cleanse-before-free — cleansed in the PG_FINALLY above */` - `src/kms/pg_vault_tde_kms_local.c:2082`: `/* nosemgrep: tde-cleanse-before-free — cleansed in the PG_FINALLY above */` - `src/tam/pg_vault_tde_tam.c:909`: `/* nosemgrep: tde-rd-tableam — to be replaced by direct heapam calls, PSQLE-213 */` - `src/tam/pg_vault_tde_tam.c:1439`: `/* nosemgrep: tde-rd-tableam — to be replaced by direct heapam calls, PSQLE-213 */` - `src/tam/pg_vault_tde_tam.c:2824`: `/* nosemgrep: tde-rd-tableam — to be replaced by direct heapam calls, PSQLE-213 */` ## Not run here - CodeQL (`security-extended`, `.github/workflows/codeql.yml`): not queried (no GITHUB_TOKEN) — [open alerts](https://github.com/labmiriade/pg_vault_tde/security/code-scanning). - The functional battery: `make ci-all`, or the Bitbucket custom pipeline `test-all`.