Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add new security audit report #1321

Merged
merged 5 commits into from
Nov 28, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 13 additions & 1 deletion NEWS.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,18 @@
# Wasmi News

## 2024-02-07 - Announcement: Transfer of Ownership
## 2024-11-27 - Wasmi Security Audit for v0.36+

In the last months Wasmi v0.36.0 and later versions have been audited by
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe remove 'In the last months' in the beginning since in the future years when someone reads this it won't be last few months.

Copy link
Member Author

@Robbepop Robbepop Nov 30, 2024

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I thought the date right above it was enough to avoid this confusion but I can remove this.

[Runtime Verification Inc.](https://runtimeverification.com/) contracted by
the [Stellar Development Foundation](https://stellar.org/foundation).

The final report can be found [here](./resources/audit-2024-11-27.pdf).

I want to thank the Stellar Development Foundation and Runtime Verification Inc.
for this highly appreciated and valuable contribution which will make Wasmi an even
more attractive option for safety critical use cases in the future.

## 2024-02-07 - Announcement: Transfer of Ownership

As of 2024-02-01, the original owner and maintainer of the Wasmi project, [Parity Technologies], has officially transferred ownership of the project to me, [Robin Freyler]. Since over 2 years I am the main developer and contributor for the project.

Expand Down
14 changes: 12 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,10 +23,20 @@

Wasmi is an efficient and lightweight WebAssembly interpreter with a focus on constrained and embedded systems.

Version `0.31.0` has been [audited by SRLabs].
## Security Audits

Wasmi is suitable for safety critical use cases and has been audited several times already.

| Wasmi Version(s) | Auditor | Contractor | Report |
|--:|:--|:--|:--|
| `0.36.0`-`0.38.0` | [Runtime Verification Inc.] | [Stellar Development Foundation] | [PDF](./resources/audit-2024-11-27.pdf) |
| `0.31.0` | [SRLabs] | [Parity Technologies] | [PDF](./resources/audit-2023-12-20.pdf) |

[Wasmtime]: https://github.com/bytecodealliance/wasmtime
[audited by SRLabs]: ./resources/security-audit-2023-12-20.pdf
[SRLabs]: https://www.srlabs.de/
[Runtime Verification Inc.]: https://runtimeverification.com/
[Stellar Development Foundation]: https://stellar.org/foundation
[Parity Technologies]: https://www.parity.io/

## Distinct Features

Expand Down
File renamed without changes.
Binary file added resources/audit-2024-11-27.pdf
Binary file not shown.