mirror of
https://github.com/headroomlabs-ai/headroom.git
synced 2026-08-27 14:17:10 -04:00
## Description
Supply-chain hardening: takes the **shipped** dependency surface from
**26 known CVEs to 0**. `pip install headroom-ai[all]` now resolves with
no known vulnerabilities (verified with Anchore syft + grype). Also
publishes a checked-in SBOM package (`sbom/`) so any user — especially
pilots running their own security review — can verify what's inside and
that we track it.
This addresses the Dependabot alerts on `main` (9 high / 4 moderate / 7
low at time of writing).
Closes #
## Type of Change
- [x] Bug fix (non-breaking change that fixes an issue)
- [ ] New feature (non-breaking change that adds functionality)
- [ ] Breaking change (fix or feature that would cause existing
functionality to change)
- [x] Documentation update
- [ ] Performance improvement
- [ ] Code refactoring (no functional changes)
## Changes Made
**Rust**
- `pyo3` 0.24 → 0.29 (GHSA-36hh-v3qg-5jq4 High, GHSA-chgr-c6px-7xpp
Med). Migrated `Python::allow_threads` → `Python::detach` (10 sites) and
added `from_py_object` to the `Clone`-deriving `#[pyclass]` types (both
required by the 0.25+ API).
- `pyo3-log` 0.12 → 0.13; `lru` 0.12 → 0.18 (GHSA-rhfx-m35p-ff5j).
**Python**
- `torch` → 2.12.1, `mem0ai` → 2.x.
- Floor-pinned transitive CVE deps via `[tool.uv]
constraint-dependencies`: `pygments>=2.20.0`,
`pydantic-settings>=2.14.2`, `gitpython>=3.1.50`, `langsmith>=0.9.0`.
- **Removed `benchmark` from the `[all]` aggregate** so the default
install is CVE-free. `lm-eval` is invoked as an external subprocess
(`python -m lm_eval`) and never imported, so it is not a true runtime
dep — it remains available via the opt-in `[benchmark]` extra. See
[Accepted Risks](#additional-notes).
**npm (build/test tooling — never shipped in the
wheel/container/published SDK)**
- `esbuild` override `>=0.28.1` in `sdk/typescript` + `plugins/openclaw`
(GHSA-g7r4-m6w7-qqqr).
- `docs/`: `@anthropic-ai/sdk` → `^0.106.0` (GHSA-p7fg-763f-g4gf),
`postcss` override to force Next.js's bundled copy ≥8.5.10
(GHSA-qx2v-qp2m-jg93); regenerated a stale `bun.lock` that carried a
**Critical** vitest/vite.
**CI**
- Pinned `pypa/gh-action-pypi-publish` `@release/v1` → `@v1.13.0`
(GHSA-vxmw-7h4f-hqxh) in `release.yml` + `publish.yml`.
**SBOM**
- New `sbom/` directory: CycloneDX 1.7 + SPDX 2.3 SBOMs, grype scan
evidence, 330-package license inventory, and a regeneration guide.
## Testing
- [ ] Unit tests pass (`pytest`) — N/A, no Python source changed
(deps/config only)
- [x] Linting passes — `cargo fmt --check` + `cargo clippy` clean on the
changed crate; 0 `.py` files changed so `ruff`/`mypy` scope is
unaffected
- [x] Type checking passes — `cargo check --workspace` (0 errors)
- [ ] New tests added — N/A (dependency bumps; covered by existing
suites)
- [x] Manual testing performed — see Real Behavior Proof
### Test Output
```text
# headroom-ai[all] product surface — the number that matters
$ grype sbom:sbom/headroom-sbom-all-extra.cdx.json
No vulnerabilities found
# full repo scan (universal lock incl. opt-in [benchmark] + dev)
$ grype sbom:sbom/headroom-sbom.cdx.json
NAME INSTALLED TYPE VULNERABILITY SEVERITY
sqlitedict 2.1.0 python GHSA-g4r7-86gm-pgqc High # [benchmark]-only, unpatchable, accepted
nltk 3.9.4 python GHSA-p4gq-832x-fm9v High # [benchmark]-only, unpatchable, accepted
# pyo3 0.29 migration — extension builds + imports + runs
$ cargo check --workspace
Finished `dev` profile [unoptimized + debuginfo] target(s)
$ maturin develop && python -c "from headroom._core import DiffCompressor, SmartCrusher; ..."
extension OK — detach + from_py_object paths exercised
# lru 0.18 — eviction path
$ cargo test -p headroom-proxy --lib drift
14 passed, 213 filtered out
# per-ecosystem npm audits
$ (cd sdk/typescript && npm audit) -> found 0 vulnerabilities
$ (cd plugins/openclaw && npm audit) -> found 0 vulnerabilities
$ (cd docs && npm audit && bun audit) -> found 0 vulnerabilities / No vulnerabilities found
```
## Real Behavior Proof
- Environment: macOS (darwin 25.4.0, arm64), Python 3.12 `.venv`, Rust
1.95 toolchain, syft 1.46.0, grype 0.115.0, bun 1.3.14, maturin 1.13.3.
- Exact command / steps: (1) `uv export --extra all --no-dev
--no-emit-project | syft → grype` for the product surface; (2) `cargo
check --workspace` + `maturin develop` + extension import/compress smoke
test; (3) `cargo test -p headroom-proxy --lib drift`; (4) `cargo fmt
--check` + `cargo clippy -p headroom-py`; (5) `npm audit` in
sdk/openclaw/docs + `bun audit` in docs.
- Observed result: `headroom-ai[all]` resolution scans clean — "No
vulnerabilities found" (179 pkgs); full/prod SBOM shows only the 2
documented accepted CVEs; pyo3 0.29 extension imports and runs (detach +
from_py_object paths exercised); drift tests 14/14 pass; cargo fmt +
clippy clean; all npm/bun audits report 0.
- Not tested: full `pytest` suite (no Python source changed);
release-profile wheel build (used dev-profile `maturin develop` for the
import proof — the extension is semantically identical).
## Review Readiness
- [x] I have performed a self-review
- [x] This PR is ready for human review
## Checklist
- [x] My code follows the project's style guidelines
- [x] I have performed a self-review of my code
- [x] I have commented my code, particularly in hard-to-understand areas
- [x] I have made corresponding changes to the documentation
(`sbom/README.md`)
- [x] My changes generate no new warnings
- [ ] I have added tests that prove my fix is effective — N/A
(dependency bumps; existing suites + scans cover it)
- [x] New and existing unit tests pass locally with my changes
- [ ] I have updated the CHANGELOG.md — N/A (Release Please
auto-generates from the conventional commit)
## Additional Notes
**Accepted risks (the 2 residual CVEs).** Both originate solely from the
EleutherAI `lm-evaluation-harness` under the **opt-in `[benchmark]`
extra**, which Headroom invokes as a subprocess (never imports):
- `sqlitedict` CVE-2024-35515 (High) — pickle deserialization; package
abandoned (last release 2021), **no upstream fix exists**.
- `nltk` CVE-2026-54293 (High) — path traversal in `nltk.data.load()`;
affects ≤3.9.4 (current latest), **no patched release**.
Neither is in `[all]`, the published wheel, or the container. They are
documented in `sbom/README.md` and will be picked up automatically once
upstream ships fixes.
**Release/CHANGELOG:** N/A items above are because this is a
dependency/security PR with no Python source changes; CHANGELOG is
Release-Please-managed via the conventional commit message.
128 lines
6.1 KiB
TOML
128 lines
6.1 KiB
TOML
[workspace]
|
||
resolver = "2"
|
||
members = [
|
||
"crates/headroom-core",
|
||
"crates/headroom-proxy",
|
||
"crates/headroom-py",
|
||
"crates/headroom-parity",
|
||
]
|
||
# headroom-py is a Python extension module — it must be built via maturin, not
|
||
# plain cargo (the "extension-module" feature tells pyo3 not to link libpython,
|
||
# which is required for `import` to work). `cargo build --workspace` without
|
||
# explicit members skips it; `cargo test --workspace` still runs its tests
|
||
# because pyo3 can dynamically link here for the cdylib used by tests.
|
||
default-members = [
|
||
"crates/headroom-core",
|
||
"crates/headroom-proxy",
|
||
"crates/headroom-parity",
|
||
]
|
||
|
||
[workspace.package]
|
||
edition = "2021"
|
||
rust-version = "1.80"
|
||
license = "Apache-2.0"
|
||
repository = "https://github.com/chopratejas/headroom"
|
||
authors = ["Headroom Maintainers"]
|
||
|
||
[workspace.dependencies]
|
||
serde = { version = "1", features = ["derive"] }
|
||
# `preserve_order` makes `serde_json::Value::Object` use IndexMap so JSON
|
||
# parse order is preserved through Value→string→Value round-trips. The
|
||
# smart_crusher port relies on this to match Python's `str(dict)` output,
|
||
# which preserves insertion order; otherwise BTreeMap's sorted-key default
|
||
# would diverge from Python on every multi-key object.
|
||
#
|
||
# `arbitrary_precision` keeps the literal numeric token from the source
|
||
# JSON intact: `Value::Number` becomes a wrapper around the original
|
||
# digit string, so `1.0` does NOT collapse to `1`, and `12345678901234567`
|
||
# does NOT lose precision through f64. Required by Realignment invariant
|
||
# I1 (byte-faithful passthrough on unmutated bytes; see REALIGNMENT/02-
|
||
# architecture.md §2.2) and PR-A4 (see REALIGNMENT/03-phase-A-lockdown.md).
|
||
#
|
||
# `raw_value` exposes `serde_json::value::RawValue`, the unparsed JSON
|
||
# fragment type. Phase B PR-B2 uses this to forward unmodified
|
||
# `messages[*]` entries as exact byte copies — the parser captures the
|
||
# original byte slice, so byte-for-byte round-trips work even with
|
||
# whitespace, key order, or escape preferences the producer chose.
|
||
# Enabled here in Phase A so PR-B2 can land as a pure consumer change.
|
||
serde_json = { version = "1", features = ["preserve_order", "arbitrary_precision", "raw_value"] }
|
||
bytes = "1"
|
||
thiserror = "1"
|
||
# `log` compat: when no tracing subscriber is active (the case inside the
|
||
# headroom-py cdylib), events are re-emitted as `log` records so pyo3-log
|
||
# can forward them to Python's logging. No effect on binaries that install
|
||
# a real subscriber.
|
||
tracing = { version = "0.1", features = ["log"] }
|
||
anyhow = "1"
|
||
clap = { version = "4", features = ["derive"] }
|
||
tokio = { version = "1", features = ["macros", "rt-multi-thread", "signal"] }
|
||
axum = "0.7"
|
||
tower = "0.5"
|
||
reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls"] }
|
||
pyo3 = { version = "0.29", features = ["abi3-py310"] }
|
||
# Forwards Rust `log` records (incl. tracing events via the `log` compat
|
||
# feature above) into Python's `logging` inside the _core extension module.
|
||
pyo3-log = "0.13"
|
||
# Phase D PR-D1: AWS SigV4 signing for native Bedrock InvokeModel route.
|
||
# `aws-sigv4` provides the canonical-request + signing-key implementation;
|
||
# `aws-config` resolves credentials from the standard provider chain
|
||
# (env vars, profiles, IMDS, ECS task role, etc); `aws-credential-types`
|
||
# exposes `Credentials` so the signer accepts whatever the chain returned.
|
||
aws-sigv4 = { version = "1", default-features = false, features = ["sign-http", "http1"] }
|
||
aws-config = { version = "1", default-features = false, features = ["behavior-version-latest", "rustls", "rt-tokio", "sso"] }
|
||
aws-credential-types = { version = "1", default-features = false }
|
||
# `Identity` lives in aws-smithy-runtime-api; the SigV4 builder
|
||
# accepts `&Identity`. Pinning the version explicitly avoids a
|
||
# silent semver bump from the transitive dep tree.
|
||
aws-smithy-runtime-api = { version = "1", default-features = false, features = ["client"] }
|
||
# PR-D4: Vertex publisher path uses GCP Application Default Credentials
|
||
# (ADC) → bearer token for the `Authorization: Bearer <token>` header.
|
||
# `gcp_auth` resolves the chain (gcloud user creds, GCE/GKE metadata
|
||
# server, service-account JSON, workload-identity federation) without
|
||
# us baking provider-specific knowledge in. The token source is wrapped
|
||
# in a `TokenSource` trait so tests inject a static-token mock.
|
||
gcp_auth = "0.12"
|
||
|
||
|
||
# ── Release profile — wheel size optimization ───────────────────────
|
||
#
|
||
# PyPI imposes a 10 GB cumulative storage limit per project. We hit it
|
||
# at version 0.21.36 (191 versions × ~213 MB/release = 10.00 GB
|
||
# exactly). Recent wheels were ~16-18 MB each, of which ~6.4 MB was
|
||
# pure debug metadata (`.strtab` + `.symtab` ELF sections; uncovered
|
||
# by post-mortem inspection of an actual production wheel).
|
||
#
|
||
# This profile shrinks each Linux wheel from ~18 MB → ~10-11 MB by:
|
||
# * Stripping symbol/string tables (~6.4 MB direct savings)
|
||
# * Link-time optimization across crate boundaries (~5-10% .text
|
||
# savings via dead-code elim across the workspace)
|
||
# * Single codegen unit (better inlining + dead-code elim, at the
|
||
# cost of slightly slower release builds)
|
||
#
|
||
# We deliberately do NOT set ``panic = "abort"``. The proxy is a
|
||
# long-lived async process — a single misbehaving request triggering
|
||
# panic-abort would terminate the whole proxy and disconnect every
|
||
# concurrent client. Accept the smaller savings; keep unwind behaviour.
|
||
#
|
||
# Estimated impact: 213 MB/release → ~130 MB/release. Buys ~30+ more
|
||
# release slots within the 10 GB ceiling at the current release
|
||
# cadence. Per-PyPI-version savings AND faster downloads for end
|
||
# users. Tradeoff: release builds take ~30-50% longer due to
|
||
# `codegen-units = 1` + LTO; acceptable for the size win.
|
||
[profile.release]
|
||
strip = "symbols"
|
||
lto = "thin"
|
||
codegen-units = 1
|
||
|
||
# Fast-to-compile profile for CI test wheels. The shipped wheel uses
|
||
# `release` (lto + codegen-units=1) for runtime/size; CI only needs a working
|
||
# extension, so trade runtime perf for ~parallel, lto-free compilation. Used
|
||
# via `maturin build --profile ci`. Does NOT affect `--release` builds.
|
||
[profile.ci]
|
||
inherits = "release"
|
||
lto = false
|
||
codegen-units = 256
|
||
opt-level = 1
|
||
strip = "none"
|
||
debug = false
|
||
incremental = false
|