chore(crypto): bump keccak from 0.1.5 to 0.1.6 in /crypto/_wasm - #7333
Conversation
avocet-bot
left a comment
There was a problem hiding this comment.
Review: denoland/std #7333 — chore(deps): bump keccak from 0.1.5 to 0.1.6 in /crypto/_wasm
Reviewed head SHA: 12ee226940ed42c2edf4304df740f5ac4b94c19b
Verdict: Approve — clean, correctly-scoped, well-documented dependency bump. No blocking issues.
What this PR changes (background for the reader)
denoland/std is the Deno standard library. Its crypto module provides hashing primitives (SHA-3, Keccak, SHAKE, etc.). Rather than implementing these in TypeScript, the hot digest code lives in a small Rust crate under crypto/_wasm/, which is compiled to WebAssembly (wasm32) and shipped as a checked-in artifact. Two things in that directory are relevant here:
crypto/_wasm/Cargo.lock— the pinned Rust dependency graph, including exact versions and content checksums.crypto/_wasm/lib/deno_std_wasm_crypto.mjs— the compiled WASM binary, embedded as a base64 string inside a JavaScript module. This is a build output that is committed to the repo, so it must be kept in sync withCargo.lock.
keccak is a low-level RustCrypto crate that implements the Keccak-f permutation. It is a transitive dependency of sha3, which backs the module's SHA-3 / SHAKE / Keccak digests. This PR bumps keccak from 0.1.5 to 0.1.6 and rebuilds the WASM artifact so it matches the new lockfile.
The change touches only two files:
Cargo.lock— thekeccakversion (0.1.5→0.1.6) and its checksum.deno_std_wasm_crypto.mjs— a single base64 line in the embedded WASM.
There are no source-code changes and no API-surface changes.
Verification performed
Checksum authenticity — verified. The new Cargo.lock checksum
cb26cec98cce3a3d96cbb7bced3c4b16e3d13f27ec56dbd62cbc8f39cfb9d653
matches the checksum published for keccak 0.1.6 in the authoritative crates.io sparse index (https://index.crates.io/ke/cc/keccak) exactly. The version is not yanked. This rules out a tampered or mis-pinned dependency.
Semver compatibility — safe. Under Cargo's pre-1.0 rules, the minor component of a 0.1.x version acts as the "major", so 0.1.5 → 0.1.6 is an API-compatible patch bump. keccak is only reached transitively through sha3; no direct call sites in this crate change, and no public API is affected.
Advisory scoping — accurate. The bump clears GHSA-3288-p39f-rqpv (low severity): older keccak versions had misspecified operand types in the opt-in ARMv8 assembly backend — technically undefined behavior, though it did not affect the assembly actually generated, and it is fixed in 0.1.6. Critically, the asm feature is opt-in and is not enabled here, and this crate compiles only for wasm32, so the affected ARMv8 code path was never built into the shipped artifact. Real-world impact of the vulnerability on Deno was effectively nil; this bump is advisory-clearing hygiene, which matches the PR description.
WASM artifact — no functional change. The diff in deno_std_wasm_crypto.mjs is a single embedded base64 line. Decoding the changed substrings confirms the only difference is the embedded panic-message source path:
- old →
-0.1.5/src/lib.rs - new →
-0.1.6/src/lib.rs
No logic/instruction bytes changed — only a debug path string that embeds the dependency version. This is exactly what a deno task build:crypto rebuild against the new lockfile should produce, and it confirms the author correctly kept the checked-in artifact in sync with Cargo.lock rather than letting the two drift.
Findings
No correctness, security, regression, concurrency, or edge-case concerns. Missing tests are not a risk here: there is no behavioral change to cover, and the existing crypto test suite already exercises the SHA-3 / Keccak digest paths that this artifact backs.
Review skill evidence
- Invoked the
pr-review-toolkit:code-reviewerClaude Code subagent (Task tool) as the primary review pass. It independently fetched the diff, authenticated the checksum againststatic.crates.ioand the crates.io API, confirmed the GHSA advisory scope, and decoded the WASM base64 diff, returning no findings at confidence ≥ 80. - Independently re-verified the checksum against the crates.io sparse index and decoded the changed base64 fragments to confirm the WASM diff is limited to the embedded version path string.
Recommendation: Approve and merge.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #7333 +/- ##
=======================================
Coverage 95.04% 95.04%
=======================================
Files 619 619
Lines 52012 52012
Branches 9450 9450
=======================================
+ Hits 49433 49434 +1
Misses 2031 2031
+ Partials 548 547 -1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Older keccak versions had misspecified operand types in the opt-in ARMv8 asm backend, technically undefined behavior even though it had no effect on the assembly actually generated (GHSA-3288-p39f-rqpv, low). The asm feature isn't enabled here and the crate targets wasm32, so the affected path was never compiled in; the compiled .wasm output is unchanged except for an embedded source-path string. Rebuilt with `deno task build:crypto` to keep the checked-in lib/ output in sync with Cargo.lock.
12ee226 to
d1f35e1
Compare
operand types in the opt-in ARMv8 asm backend, which the advisory
flags as undefined behavior even though it had no effect on the
assembly actually generated (GHSA-3288-p39f-rqpv, low)
The asm feature isn't enabled here and the crate only targets
wasm32, so the affected code path was never compiled in. Rebuilt
the checked-in crypto/_wasm/lib output with
deno task build:cryptoto keep it in sync with Cargo.lock; the resulting .wasm differs only
in an embedded source-path debug string, with no functional change.