tschneidereit opened PR #14628 from tschneidereit:oss-scanner to bytecodealliance:main:
This adds a
Dockerfileand a threat model description to be consumed by the OSS Scanner program, following the program's template.The
Dockerfilebuilds quite a bunch of stuff, which is by design: the image build process happens on much larger machines than where they're then run (16 instead of 2 cores, and something more than the 8GB it gets at runtime.)The threat model largely describes our stability tiers and gives some information on what to focus on. The one place where I decided to deviate a bit is to say that issues with the aarch64 backend should be considered vulnerabilities and reported as such, even though that backend is tier 2. The reason is that a lack of continuous fuzzing is what's holding that backend back from tier 1, and I think with this initiative (plus other auditing we're doing right now) we should be able to reconsider this soon.
<!--
Please make sure you include the following information:
If this work has been discussed elsewhere, please include a link to that
conversation. If it was discussed in an issue, just mention "issue #...".Explain why this change is needed. If the details are in an issue already,
this can be brief.Our development process is documented in the Wasmtime book:
https://docs.wasmtime.dev/contributing-development-process.htmlPlease review the Bytecode Alliance's AI tool usage policy at
https://github.com/bytecodealliance/governance/blob/main/AI_TOOL_POLICY.mdPlease ensure all communication follows the code of conduct:
https://github.com/bytecodealliance/wasmtime/blob/main/CODE_OF_CONDUCT.md
-->
tschneidereit requested alexcrichton for a review on PR #14628.
tschneidereit requested wasmtime-default-reviewers for a review on PR #14628.
tschneidereit commented on PR #14628:
Oh, and I tested the
Dockerfilelocally, and can confirm that it build successfully, and passes the smoke tests the build process runs. The resulting image is something like 65GB in size—well below the 120GB limit.
:thumbs_up: pchickey submitted PR review.
pchickey has enabled auto merge for PR #14628.
pchickey added PR #14628 Add required info for Anthropic's OSS Scanner program to the merge queue.
:memo: alexcrichton submitted PR review:
I'm fine with these being follow-ups, but I'm hesitant to duplicate so much of our documentation in these docs because it seems like it'll inevitable get pretty far out of sync and we'll forget to update it
:speech_balloon: alexcrichton created PR review comment:
You can drop
--lockedfrom all these commands, we test in CI it's not necessary
:speech_balloon: alexcrichton created PR review comment:
I'd probably say the tests here and
cargo testabove can be skipped
:speech_balloon: alexcrichton created PR review comment:
These seem like they can be dropped
:speech_balloon: alexcrichton created PR review comment:
I suspect nothing is going to read these warning messages, but also the fuzzers should always build, so perhaps just skip this?
:speech_balloon: alexcrichton created PR review comment:
Could this perhaps try to read https://github.com/bytecodealliance/wasmtime/blob/a8d33e523206646ca2850bac2744571b4827961b/.github/actions/install-rust/action.yml#L41 and use that version of rustc? That can be the default toolchain for this whole build, I don't think there's any need to switch between stable/nightly
:speech_balloon: alexcrichton created PR review comment:
This is probably better modeled as
./target/debug/wasmtime wast *.wast
:speech_balloon: alexcrichton created PR review comment:
Given the nature of how much this all changes over time, could this be omitted and deferred to our own
docs/folder?
:speech_balloon: alexcrichton created PR review comment:
This is mostly just a duplication of our other docs, right?
:speech_balloon: alexcrichton created PR review comment:
We've git a skill in-repo for reduction, could this point there?
:speech_balloon: alexcrichton created PR review comment:
Is this useful to include because all tests are always passing?
:speech_balloon: alexcrichton created PR review comment:
This is mostly a duplication of the wasmtime-auditor skill I think?
tschneidereit removed PR #14628 Add required info for Anthropic's OSS Scanner program from the merge queue.
:memo: tschneidereit submitted PR review.
:speech_balloon: tschneidereit created PR review comment:
it's useful to include because it primes the build cache, so modifications to individual files go more quickly. The machines building the image are much larger than the ones running it, so this kind of front-loading is apparently advisable.
:memo: tschneidereit submitted PR review.
:speech_balloon: tschneidereit created PR review comment:
See my other comments on these things: this is meant to prime the builds for running on the smaller machines after the image has been built.
:memo: tschneidereit submitted PR review.
:speech_balloon: tschneidereit created PR review comment:
(and note that it doesn't run the tests, just build them)
:memo: tschneidereit submitted PR review.
:speech_balloon: tschneidereit created PR review comment:
The template says "Run the cheap tests so you know the image works, but do not let a failing test abort the build", which is why it's done this way.
Also, apparently the primary contact will be emailed, so we'll have to see whether having that be a mailing list of all core maintainers will be the right call or not
Last updated: Oct 11 2026 at 04:10 UTC