chore(deps): update ghcr.io/cosmian/kms docker tag to v5.28.0 - #351
Merged
Merged
Conversation
📊 V0.6-QA-1 Micro Benchmark AdvisoryThis run is advisory only (3×3s vs committed baseline); it never fails the PR. See |
renovate
Bot
force-pushed
the
renovate/ghcr.io-cosmian-kms-5.x
branch
from
October 2, 2026 09:10
51c3243 to
d39b4e4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.27.1→5.28.0Release Notes
Cosmian/kms (ghcr.io/cosmian/kms)
v5.28.0Compare Source
🔒 Security
Extractable/NeverExtractablenot enforced on key export paths (GHSA-8mmx-f92q-2gq8):Get,Export, and PKCS#12 export now enforceExtractable/NeverExtractable, deny non-extractable keys withResultReason::Not_Extractable, require a non-empty password for sensitive PKCS#12 exports, and unconditionally latch server-managedNeverExtractableacross creation/import andReKey/ReKeyKeyPairrotations (#1198)*bypassable viaAtomicOperation::UpsertandCertifydestination overwrite (GHSA-pvw2-jxwc-95xq):Database::atomicnow screens bothCreateandUpsertagainst the reserved-UID guard,Certifyvalidates/authorizes destination UIDs, and all backends (SQLite, PostgreSQL, MySQL, Redis) atomically enforce ownership onUpsertwithout partial tag mutations (#1198)Sensitive/Extractableattribute stripping via read-onlyGetgrant (GHSA-c75c-3cmm-48h7):DeleteAttributenow rejects server-managed attributes (includingSensitiveandExtractable) under both the by-value and by-tag branches, and mutating these attributes requires explicit operation grants or ownership instead of a read-onlyGetgrant (#1198)sign-intermediateissues CA certificates to any Vault token (COSMIAN-2026-022, #1234):POST /v1/{pki_mount}/root/sign-intermediatenow requires the caller's KMS identity (spire:<AppRole name>) to hold thecertifygrant on the CA private key; CA keys are looked up only among keys owned bydefault_username, and CSRs requestingbasicConstraintsare rejected to preservepathlen:0(Upgrade action: runckms access-rights grant spire:<AppRole name> certify --object-uid <ca-private-key-uid>)sign,GET /keys/{name}, list, delete) now restricts lookups to keys owned by the caller, preventing key substitution via shared tags; creating an existing key name is idempotent/.well-known/jwks.jsonnow publishes only keys owned bydefault_username, preventing unauthorized key injection via shared keysPOST/DELETE /v1/crypto/keys/{kid}/tagsnow enforceadd_attribute/delete_attributepermissions instead of general read accessC_GetAttributeValueandC_Encrypt(COSMIAN-2026-026, #1234): caller buffer length is verified before writing output to prevent buffer overflow; returnsCKR_BUFFER_TOO_SMALL;C_GenerateKeynow rejects a nullphKeywithCKR_ARGUMENTS_BADDestroypreserves issuer link and revocation metadata so destroyed certificates remain reported as revoked (RFC 5280 §3.3); certificate serials are generated as random 159-bit integers instead of SHA-1(SPKI) to avoid serial collisions onReCertify; OCSP response cache is keyed by fullCertID, bounded, respectsnextUpdate, and skips cachingunknown; OCSP requires CA match for allCertIDs; automatic CRL regeneration runs on behalf of the CA owner; stored CRL is re-read from the DB every 60 s; wrapped CA keys are unwrapped for CRL/OCSP signing;Validate/ImportCRL cache enforces 5-minute freshness and does not hold locks during network I/Okms_public_urlprefix match in CRL fetching (COSMIAN-2026-028, #1234): URL comparison in CRL fetching compares parsed scheme, host, port, and base path, rejecting URLs with embedded credentials to prevent SSRF bypassDeriveKeycurve validation to check the OpenSSL keyIdactually constructed from each referenced object's key material, closing anEd25519/X25519 key-type confusion edge case (both curves share a 32-byte raw key length) (#1170)smol-toml1.6.1 → 1.8.0 (CVE-2026-85730),axum-server0.7 → 0.8 to drop unmaintainedrustls-pemfile(RUSTSEC-2025-0134, #1180),rustls0.23.43 → 0.23.45, and upgradedkubeto remove unmaintained deps🚀 Features
Audit Logging & SIEM Export
id,prev_hash, androw_hash(SHA-256), fsync'd after every write; truncation/reordering/modification breaks the chain and is detected by the newckms audit verifycommandBatchItemaudit events with a shared UUID v4request_id(fan-out of batchRequestMessagecalls) for SIEM/log correlationckms audit verify --path <file|dir>CLI command: verifies eachrow_hashandprev_hashlink, validates every*.jsonlchain in a directory, and confirms sealedaudit:reanchorevidence files still exist and hash-match on diskto_cef_line()) for direct ArcSight/Splunk/QRadar ingestion, with adevicePayloadId=<uuid>extension whenrequest_idis presentaudit:evictionsentinel event is written into the chain so lost events are detectable byckms audit verifyX-Forwarded-For, preventing client IP spoofing in audit logs (--audit-trusted-proxy-cidrs)--audit-failure-mode continue|reject):rejectreturns HTTP 503 when an event cannot be queuedaudit:torn-write-recoveredsentinel), tampered rows trigger seal-and-roll to a forensic<name>.<ts>.<hex>.corrupt.<ext>file plus a freshaudit:reanchorchain, the entire hash chain is verified on every boot, a best-effort cross-platform exclusive lock prevents two KMS instances corrupting a shared-volume log, and an unwritable path self-heals via periodic retry--audit-file-max-size-byteswrite-stop cap (no rotation/retention)SPIFFE / Workload Identity (#1206)
--jwt-svid-auth/KMS_JWT_SVID_AUTH/[idp_auth] jwt_svid_auth): a validated JWT without anemailclaim is accepted whensubstarts withspiffe://, becoming the KMS user/owner (audit methodJwtSvid); audience is required, and mTLS client-cert CN takes precedence over JWT-SVIDckms login spire --audience <aud> [--spiffe-id <id>] [--socket-path <path|uri>](SPIRE Agent Workload API)POST /ui/login_svidBFF endpoint andGET /ui/auth_methodadvertisingSPIFFE; thekms setupwizard now asks whether JWT/OIDC providers issue SPIFFE JWT-SVIDsX25519 ECDH (#1170)
DeriveKey, including repeated base-object identifiers for asymmetric two-key derivation (DeriveKey::new_single_base/new_asymmetric); shared secrets are stored as non-extractableSecretDatawith reciprocal derivation linksckms derive-key --x25519 --private-key-id <ID> --peer-public-key-id <ID>and a WASM exportderive_key_asymmetric_ttlv_requestfor the Web UISecretDataoutput)JOSE / REST Crypto API (#1033)
/v1/crypto/decrypt(RFC 7518 §4.6):ECDH-ES,ECDH-ES+A128KW,ECDH-ES+A256KWwithA128GCM/A192GCM/A256GCMcontent encryption, over P-256/P-384/P-521 (FIPS) and X25519 (non-FIPS)/v1/crypto/keyskey creation forECDH-ES*algorithms (KeyAgreement usage), and publish X25519 static public keys via/.well-known/jwks.json(kty=OKP)ecdh_key_agreementprimitive and RFC 7518 Appendix C / NIST SP 800-56A Concat KDF tocosmian_kms_cryptoDatabase TDE Integrations (#1162)
cosmian_pkcs11, and IBM Db2 LUW TDE support via the native IBM GSKit KMIP client over mutual TLS🐛 Bug Fixes
Database
kms.keys.active.countmetric never updating on PostgreSQL (JSONB?operator applied to aVARCHARcolumn); now castsobject::jsonband logs failures atwarn!level (#1203)rediss://) for the Redis-findex backend by enablingtls-native-tls/tokio-native-tls-comp(#1195, #1204)(tag, id)index on all three SQL backends to turn tag-basedLocatelookups into index-only scans (#1224)find_by_rotate_name), the auto-rotation scheduler, and ObjectType filters on PostgreSQL/SQLite, and makekms.keys.active.countfilter on theObjectTypeattribute instead of parsing every row's JSON (#1224)Locate-by-tags as per-tagINNER JOINs withEXISTS-based read-access probes, pushingLIMIT/server cap and destroyed-object exclusion into the query so the DB stops after the requested page (#1224)Permissions / Access Control
GET /access/obtainedand KMIPLocatenow include permissions granted to the wildcard user*, consistent with per-object permission checks (#1188)RedisWithFindex::list_user_operations_grantedmispairing permission entries with objects byzip-ing two independently-orderedHashMaps instead of joining by object uid (#1188)Cache
JOSE
/.well-known/jwks.jsonpublishing EC keys authorized forKeyAgreement(but notVerify) with a signatureuse/algclaim (ES256/ES384) instead ofuse=encwith noalg♻️ Refactor
crate/server: introduce the audit middleware/extension-injection architecture andAuditFileStoresingle-writer task, splitting the KMIP route module intoroutes/kmip/(handlers.rs,audit.rs)crate/access: addaudit::{event, hash, cef, file_hash}with canonical event hashing, CEF serialization, and file-tail hash helperscrate/server_database: rework the SQLLocatequery builder (locate_query.rs) and shared SQL/MySQL/SQLite query files for index-backed lookups and JSONB-aware predicatescrate/kmip: widenDeriveKeyidentifier fields toVec(KMIP 1.4unique_identifierand 2.1object_unique_identifier) for asymmetric derivationcrate/crypto: addconcat_kdf(RFC 7518 Appendix C) and a generic P-256/P-384/P-521ecdh_key_agreementprimitive🧪 Testing
mise test:audit(hash-chain integrity, required fields),mise test:cef(CEF v27 format + UDP/TCP syslog with RFC 6587 octet-counting),mise test:siem(Filebeat/Fluent Bit),mise test:monitoring(OTel Collector + VictoriaMetrics + Grafana), plus live-audit-fixture generation and OpenSearch/Splunk JSONL compat checks in CI (#1115, #1150, #1131)test:ase) and IBM Db2 LUW (test:db2) Docker-based TDE integration suites (#1162)DeriveKeyKMIP vectors, RFC 7518 Appendix C Concat KDF known-answer vectors, and an ECDH-ES test suite (round trips,kidlink-following, AAD binding, and negative key-confusion/FIPS-rejection cases)spire-jwt-svid) minting an SVID against a live SPIRE serveralways-sensitiveand attribute-read-only security regression tests, plus wildcard-grant and shared-DB (KMS_TEST_DB=postgresql|mysql|redis-findex) test coverage — the full external-DB nextest run now passes 2085/2085 (#1188)mise testto run every task under.mise/tasks/test/, auto-skipping groups whose infra/credentials are unavailable, with a final PASS/SKIP/FAIL summary (#1188)⚙️ Build
VERSIONINFOresources inckms.exe,cosmian_kms.exe,cosmian_pkcs11.dll, andcosmian_cng.dllbrace-expansion,js-yaml,nanoid,moment,@vitest/mocker) (#1163, #1185, #1230, #1231)test_all.yml; pin Splunk/OpenSearch images and regenerate live audit fixtures instead of static samples📚 Documentation
configuration/audit-logs.md,configuration/cef-export.md,configuration/siems.md) with Mermaid sequence diagrams, plus ADRs for the single-writer design, middleware extension injection, CEF export format, always-start recovery, and SPIFFE JWT-SVID authenticationChaCha20Poly1305sealing workflowotlp-metrics.md→otlp-telemetry.md) and document the Windows signing-certificate trust model inkms_clients/installation.mdConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.