Skip to content

chore(crypto): bump keccak from 0.1.5 to 0.1.6 in /crypto/_wasm - #7333

Merged
piscisaureus merged 1 commit into
mainfrom
deps/security-bumps
Sep 25, 2026
Merged

piscisaureus merged 1 commit into
mainfrom
deps/security-bumps

Conversation

@piscisaureus

Copy link
Copy Markdown
Member
  • keccak 0.1.5 -> 0.1.6 in crypto/_wasm - fixes misspecified
    operand types in the opt-in ARMv8 asm backend, which the advisory
    flags as undefined behavior even though it had no effect on the
    assembly actually generated (GHSA-3288-p39f-rqpv, low)

The asm feature isn't enabled here and the crate only targets
wasm32, so the affected code path was never compiled in. Rebuilt
the checked-in crypto/_wasm/lib output with deno task build:crypto
to keep it in sync with Cargo.lock; the resulting .wasm differs only
in an embedded source-path debug string, with no functional change.

@avocet-bot avocet-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review: denoland/std #7333 — chore(deps): bump keccak from 0.1.5 to 0.1.6 in /crypto/_wasm

Reviewed head SHA: 12ee226940ed42c2edf4304df740f5ac4b94c19b
Verdict: Approve — clean, correctly-scoped, well-documented dependency bump. No blocking issues.

What this PR changes (background for the reader)

denoland/std is the Deno standard library. Its crypto module provides hashing primitives (SHA-3, Keccak, SHAKE, etc.). Rather than implementing these in TypeScript, the hot digest code lives in a small Rust crate under crypto/_wasm/, which is compiled to WebAssembly (wasm32) and shipped as a checked-in artifact. Two things in that directory are relevant here:

  • crypto/_wasm/Cargo.lock — the pinned Rust dependency graph, including exact versions and content checksums.
  • crypto/_wasm/lib/deno_std_wasm_crypto.mjs — the compiled WASM binary, embedded as a base64 string inside a JavaScript module. This is a build output that is committed to the repo, so it must be kept in sync with Cargo.lock.

keccak is a low-level RustCrypto crate that implements the Keccak-f permutation. It is a transitive dependency of sha3, which backs the module's SHA-3 / SHAKE / Keccak digests. This PR bumps keccak from 0.1.5 to 0.1.6 and rebuilds the WASM artifact so it matches the new lockfile.

The change touches only two files:

  1. Cargo.lock — the keccak version (0.1.5 → 0.1.6) and its checksum.
  2. deno_std_wasm_crypto.mjs — a single base64 line in the embedded WASM.

There are no source-code changes and no API-surface changes.

Verification performed

Checksum authenticity — verified. The new Cargo.lock checksum
cb26cec98cce3a3d96cbb7bced3c4b16e3d13f27ec56dbd62cbc8f39cfb9d653
matches the checksum published for keccak 0.1.6 in the authoritative crates.io sparse index (https://index.crates.io/ke/cc/keccak) exactly. The version is not yanked. This rules out a tampered or mis-pinned dependency.

Semver compatibility — safe. Under Cargo's pre-1.0 rules, the minor component of a 0.1.x version acts as the "major", so 0.1.5 → 0.1.6 is an API-compatible patch bump. keccak is only reached transitively through sha3; no direct call sites in this crate change, and no public API is affected.

Advisory scoping — accurate. The bump clears GHSA-3288-p39f-rqpv (low severity): older keccak versions had misspecified operand types in the opt-in ARMv8 assembly backend — technically undefined behavior, though it did not affect the assembly actually generated, and it is fixed in 0.1.6. Critically, the asm feature is opt-in and is not enabled here, and this crate compiles only for wasm32, so the affected ARMv8 code path was never built into the shipped artifact. Real-world impact of the vulnerability on Deno was effectively nil; this bump is advisory-clearing hygiene, which matches the PR description.

WASM artifact — no functional change. The diff in deno_std_wasm_crypto.mjs is a single embedded base64 line. Decoding the changed substrings confirms the only difference is the embedded panic-message source path:

  • old → -0.1.5/src/lib.rs
  • new → -0.1.6/src/lib.rs

No logic/instruction bytes changed — only a debug path string that embeds the dependency version. This is exactly what a deno task build:crypto rebuild against the new lockfile should produce, and it confirms the author correctly kept the checked-in artifact in sync with Cargo.lock rather than letting the two drift.

Findings

No correctness, security, regression, concurrency, or edge-case concerns. Missing tests are not a risk here: there is no behavioral change to cover, and the existing crypto test suite already exercises the SHA-3 / Keccak digest paths that this artifact backs.

Review skill evidence

  • Invoked the pr-review-toolkit:code-reviewer Claude Code subagent (Task tool) as the primary review pass. It independently fetched the diff, authenticated the checksum against static.crates.io and the crates.io API, confirmed the GHSA advisory scope, and decoded the WASM base64 diff, returning no findings at confidence ≥ 80.
  • Independently re-verified the checksum against the crates.io sparse index and decoded the changed base64 fragments to confirm the WASM diff is limited to the embedded version path string.

Recommendation: Approve and merge.

@codecov

codecov Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 95.04%. Comparing base (2958335) to head (d1f35e1).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #7333   +/-   ##
=======================================
  Coverage   95.04%   95.04%           
=======================================
  Files         619      619           
  Lines       52012    52012           
  Branches     9450     9450           
=======================================
+ Hits        49433    49434    +1     
  Misses       2031     2031           
+ Partials      548      547    -1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@piscisaureus piscisaureus changed the title chore(deps): bump keccak from 0.1.5 to 0.1.6 in /crypto/_wasm chore(crypto): bump keccak from 0.1.5 to 0.1.6 in /crypto/_wasm Sep 25, 2026
Older keccak versions had misspecified operand types in the opt-in
ARMv8 asm backend, technically undefined behavior even though it
had no effect on the assembly actually generated
(GHSA-3288-p39f-rqpv, low). The asm feature isn't enabled here and
the crate targets wasm32, so the affected path was never compiled
in; the compiled .wasm output is unchanged except for an embedded
source-path string. Rebuilt with `deno task build:crypto` to keep
the checked-in lib/ output in sync with Cargo.lock.
@piscisaureus
piscisaureus merged commit f834d02 into main Sep 25, 2026
17 checks passed
@piscisaureus
piscisaureus deleted the deps/security-bumps branch September 25, 2026 17:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants