Skip to content

Build request 24/9/26 - #70

Merged
jk89 merged 10 commits into
buildfrom
develop
Sep 25, 2026
Merged

jk89 merged 10 commits into
buildfrom
develop

Conversation

@jk89

@jk89 jk89 commented Sep 24, 2026

Copy link
Copy Markdown
Member

Build after audit findings remediation final merge. PRs included

jk89 and others added 9 commits May 20, 2026 14:53
…3 constraints, four jest tests per path (PLONK zkp0, Groth16 zkp14) with 2 failing per suite (rogue exit_code and vk_root not rejected, 4 pass 4 fail total), save_sp1_vk_root binary and SP1_VK_ROOT constant added as shared infra, changelog documenting finding, response and results
…nts added to zkp0.ts (PLONK) and zkp14.ts (Groth16), all regression tests pass (8 pass 0 fail), changelog updated
…ed (src/groth/vendor.ts) and threaded through createZkp14 (src/groth/recursion/zkp14.ts), prove_zkps.ts and all three Groth16 plans so zkp14 pi-pinning branches per vendor (SP1 exit_code/vk_root, risc0 control-root/bn254-control-id, snarkjs none) instead of hardcoding SP1's constraints on every Groth16 path, risc0 control-root and bn254-control-id derived and cross-validated against Solidity source and a self-verified real proof in pairing-utils (src/risc0_control_id.rs + save_risc0_vk_root binary, surfaced to TS via src/risc0_control_id.ts / risc0_control_id_v3.0.6.json), non-tautological verifiers added per vendor and proof system (src/risc_zero/verify_risc_zero.ts, src/sp1/verify_sp1_groth16.ts, src/sp1/verify_sp1_plonk.ts, src/snarkjs/verify_snarkjs.ts) each re-deriving the pi-digest from the real public inputs and asserting it equals proof.publicOutput.rightOut while pinning proof.publicOutput.subtreeVkDigest to an independently-known node vk digest, four adjacent e2e specs (src/risc_zero/e2e.spec.ts, src/sp1/e2e_groth16.spec.ts, src/sp1/e2e_plonk.spec.ts, src/snarkjs/e2e.spec.ts) running each real conversion pipeline end to end and checking the output through those verifiers rather than a tautological verify(proof, vk), all four passing, vendor_branch_regression.spec.ts cross-testing real sp1/risc0 proofs against the wrong vendor branches (4 pass), vk-tree user script added (npm run vk-tree, src/build_vk_tree.ts + src/{groth,plonk}/zkp_tree.ts + src/{groth,plonk}/compile_leaf.ts + src/utils/spawn_worker.ts) recomputing a path's subtreeVkDigest straight from the compiled leaf and layer1/node circuits with one subprocess per leaf to bound WASM memory, confirmed digit-for-digit equal to the real e2e output for plonk/risc0/snarkjs, documented in README, jest runner infra fixed so the specs can run (root_dir walks up to the package.json, processPool spawns with explicit env, jest.setup wires LogPrinter), example-generators added as a submodule and example-proofs regenerated
…ts from independent audit fixes landing on the same lines. In CHANGELOG.md, the 18fa3 entry (19/5/26) was reunited into a single block and reordered to sit correctly between EC50D (26/5/26) and B1114 (18/5/26), with every entry from both branches preserved byte for byte. In src/plonk/recursion/zkp0.ts, both fixes were kept together, the pi2/pi3 pinning from the 18fa3 fix and the ten G1 on curve checks from the EC50D fix, which are independent constraints with no overlap. Also audited the files both branches touched but that auto merged without conflict, src/groth/recursion/prove_zkps.ts, src/groth/vk.ts, and README.md, and confirmed both sides' changes are present in each with no dropped logic and no stale references to the renamed AuXWitness.loadFromPath API anywhere in the tree.
…CHORE/integration-audit-fix-develop-18-9-26-final
…p-18-9-26-final no conflicts, updated CHANGELOG.md
…op-18-9-26-final

Chore/integration audit fix develop 18 9 26 final

Accepting npm audit issues for now
@jk89
jk89 requested a review from Kirol54 as a code owner September 24, 2026 12:18
@github-actions

Copy link
Copy Markdown

Quality Gate Report

Generated: 9/24/2026, 12:18:18 PM

Overall Status: FAIL

Required checks failed:

  • npm audit

Summary

  • Passed: 2
  • Failed: 4
  • Skipped: 1

Detailed Results

Dependencies - PASS

Type: REQUIRED

Message: Dependencies installed successfully

Scripts Check - FAIL

Type: Optional

Message: Missing scripts: test:unit, test:integration

Details
Expected: test:unit, test:integration, test:e2e
Found: test:e2e
Missing: test:unit, test:integration

npm audit - FAIL

Type: REQUIRED

Message: Vulnerabilities found (threshold: moderate)

Hint: npm audit fix

Details
# npm audit report

@babel/core  <=7.29.0
@babel/core: Arbitrary File Read via sourceMappingURL Comment - https://github.com/advisories/GHSA-4x5r-pxfx-6jf8
fix available via `npm audit fix`
node_modules/@babel/core

@babel/plugin-transform-modules-systemjs  7.12.0 - 7.29.0
Severity: high
@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input - https://github.com/advisories/GHSA-fv7c-fp4j-7gwp
fix available via `npm audit fix`
node_modules/@babel/plugin-transform-modules-systemjs

@humanfs/node  <0.16.8
Severity: moderate
humanfs: Recursive copy follows symlinked files and copies data from outside the source tree - https://github.com/advisories/GHSA-p498-v437-472g
fix available via `npm audit fix`
node_modules/@humanfs/node

baseline-browser-mapping  >=2.0.0 <2.11.0
Severity: moderate
baseline-browser-mapping process termination on invalid input causes denial of service - https://github.com/advisories/GHSA-w5vr-8v7q-w6rv
fix available via `npm audit fix`
node_modules/baseline-browser-mapping

brace-expansion  <=1.1.17 || 2.0.0 - 2.1.3 || 3.0.0 - 5.0.8
Severity: high
brace-expansion: Large numeric range defeats documented `max` DoS protection - https://github.com/advisories/GHSA-jxxr-4gwj-5jf2
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups - https://github.com/advisories/GHSA-3jxr-9vmj-r5cp
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups - https://github.com/advisories/GHSA-3jxr-9vmj-r5cp
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups - https://github.com/advisories/GHSA-3jxr-9vmj-r5cp
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash - https://github.com/advisories/GHSA-mh99-v99m-4gvg
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash - https://github.com/advisories/GHSA-mh99-v99m-4gvg
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash - https://github.com/advisories/GHSA-mh99-v99m-4gvg
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation - https://github.com/advisories/GHSA-rgw5-rvv9-x895
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation - https://github.com/advisories/GHSA-rgw5-rvv9-x895
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation - https://github.com/advisories/GHSA-rgw5-rvv9-x895
fix available via `npm audit fix`
node_modules/@typescript-eslint/typescript-estree/node_modules/brace-expansion
node_modules/brace-expansion
node_modules/glob/node_modules/brace-expansion

browserslist  <=4.28.6
Severity: high
Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM - https://github.com/advisories/GHSA-c83g-rgw3-j3cx
Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) - https://github.com/advisories/GHSA-73wf-gq98-2v4g
fix available via `npm audit fix`
node_modules/browserslist

js-yaml  <=3.15.1 || 4.0.0 - 4.3.1
Severity: high
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases - https://github.com/advisories/GHSA-h67p-54hq-rp68
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases - https://github.com/advisories/GHSA-h67p-54hq-rp68
js-yaml: YAML merge-key chains can force quadratic CPU consumption - https://github.com/advisories/GHSA-52cp-r559-cp3m
js-yaml: YAML merge-key chains can force quadratic CPU consumption - https://github.com/advisories/GHSA-52cp-r559-cp3m
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported - https://github.com/advisories/GHSA-5p4m-2wfm-xmqj
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported - https://github.com/advisories/GHSA-5p4m-2wfm-xmqj
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources - https://github.com/advisories/GHSA-2883-xcg3-v3hh
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources - https://github.com/advisories/GHSA-2883-xcg3-v3hh
fix available via `npm audit fix`
node_modules/@istanbuljs/load-nyc-config/node_modules/js-yaml
node_modules/js-yaml

ws  8.0.0 - 8.20.1
Severity: high
ws: Uninitialized memory disclosure - https://github.com/advisories/GHSA-58qx-3vcg-4xpx
ws: Memory exhaustion DoS from tiny fragments and data chunks - https://github.com/advisories/GHSA-96hv-2xvq-fx4p
fix available via `npm audit fix`
node_modules/ws
  ethers  6.0.0-beta.1 - 6.16.0
  Depends on vulnerable versions of ws
  node_modules/ethers

9 vulnerabilities (1 low, 3 moderate, 5 high)

To address all issues, run:
  npm audit fix

Build - PASS

Type: REQUIRED

Message: Build completed successfully

Prettier - FAIL

Type: Optional

Message: 76 file(s) need formatting

Hint: npm run format

Linter - FAIL

Type: Optional

Message: 21 error(s), 0 warning(s)

Hint: npm run lint

Details
> @nori-zk/proof-conversion@0.8.29 lint
> eslint src/*


/home/runner/actions/_work/proof-conversion/proof-conversion/src/groth/adcd3_regression.spec.ts
  67:21  error  '_' is assigned a value but never used  @typescript-eslint/no-unused-vars
  72:18  error  '_' is assigned a value but never used  @typescript-eslint/no-unused-vars
  77:18  error  '_' is assigned a value but never used  @typescript-eslint/no-unused-vars
  90:21  error  '_' is assigned a value but never used  @typescript-eslint/no-unused-vars

/home/runner/actions/_work/proof-conversion/proof-conversion/src/groth/adcd3_vk_regression.spec.ts
  73:27  error  '_' is assigned a value but never used  @typescript-eslint/no-unused-vars
  78:22  error  '_' is assigned a value but never used  @typescript-eslint/no-unused-vars
  83:22  error  '_' is assigned a value but never used  @typescript-eslint/no-unused-vars
  88:20  error  '_' is assigned a value but never used  @typescript-eslint/no-unused-vars

/home/runner/actions/_work/proof-conversion/proof-conversion/src/groth/recursion/18fa3_regression.spec.ts
  27:14  error  Unexpected any. Specify a different type  @typescript-eslint/no-explicit-any

/home/runner/actions/_work/proof-conversion/proof-conversion/src/groth/recursion/vendor_branch_regression.spec.ts
  30:17  error  Unexpected any. Specify a different type  @typescript-eslint/no-explicit-any
  31:19  error  Unexpected any. Specify a different type  @typescript-eslint/no-explicit-any

/home/runner/actions/_work/proof-conversion/proof-conversion/src/plonk/recursion/witness_tracker.ts
  29:10  error  'G2Line' is defined but never used  @typescript-eslint/no-unused-vars

/home/runner/actions/_work/proof-conversion/proof-conversion/src/risc0_control_id_v3.0.6.json
  0:0  warning  File ignored because no matching configuration was supplied

/home/runner/actions/_work/proof-conversion/proof-conversion/src/sha/sha_hash.ts
  1:33  error  'Field' is defined but never used     @typescript-eslint/no-unused-vars
  1:48  error  'Provable' is defined but never used  @typescript-eslint/no-unused-vars

/home/runner/actions/_work/proof-conversion/proof-conversion/src/sp1/e2e_plonk.spec.ts
  2:42  error  'Poseidon' is defined but never used  @typescript-eslint/no-unused-vars
  2:52  error  'Provable' is defined but never used  @typescript-eslint/no-unused-vars

/home/runner/actions/_work/proof-conversion/proof-conversion/src/sp1_vk_root_v6.1.0.json
  0:0  warning  File ignored because no matching configuration was supplied

✖ 18 problems (16 errors, 2 warnings)

Unit Tests - SKIPPED

Type: Info

Message: test:unit script not found


Actionable Insights

  • Add unit tests: "test:unit": "for file in $(find . -name '*.unit.spec.ts'); do npm run test -- \"$file\" || exit 1; done"
  • Add integration tests: "test:integration": "for file in $(find . -name '*.integration.spec.ts'); do npm run test -- \"$file\" || exit 1; done"
  • Fix Vulnerabilities: npm audit fix (or npm audit fix --force for breaking changes)
  • Auto-fix formatting: npx prettier --write "**/*.{ts,js,json,md}"
  • Linting Errors: Fix the linting errors shown above and run npm run lint locally to verify.

Configuration

Quality gate configured via environment variables.

Check Enabled Required
Dependencies true true
Build true true
Scripts true false
npm audit true true (level: moderate)
Prettier true false (dep: prettier)
Linter true false (dep: eslint)
Unit Tests true false

Note: Integration and E2E tests are checked for existence but run in CI/CD pipeline.

@github-actions

Copy link
Copy Markdown

Quality Gate Report

Generated: 9/25/2026, 11:46:30 AM

Overall Status: PASS

Warnings: 3 optional check(s) failed


Summary

  • Passed: 3
  • Failed: 3
  • Skipped: 1

Detailed Results

Dependencies - PASS

Type: REQUIRED

Message: Dependencies installed successfully

Scripts Check - FAIL

Type: Optional

Message: Missing scripts: test:unit, test:integration

Details
Expected: test:unit, test:integration, test:e2e
Found: test:e2e
Missing: test:unit, test:integration

npm audit - PASS

Type: REQUIRED

Message: No vulnerabilities found at moderate level or above

Build - PASS

Type: REQUIRED

Message: Build completed successfully

Prettier - FAIL

Type: Optional

Message: 76 file(s) need formatting

Hint: npm run format

Linter - FAIL

Type: Optional

Message: 21 error(s), 0 warning(s)

Hint: npm run lint

Details
> @nori-zk/proof-conversion@0.8.29 lint
> eslint src/*


/home/runner/actions/_work/proof-conversion/proof-conversion/src/groth/adcd3_regression.spec.ts
  67:21  error  '_' is assigned a value but never used  @typescript-eslint/no-unused-vars
  72:18  error  '_' is assigned a value but never used  @typescript-eslint/no-unused-vars
  77:18  error  '_' is assigned a value but never used  @typescript-eslint/no-unused-vars
  90:21  error  '_' is assigned a value but never used  @typescript-eslint/no-unused-vars

/home/runner/actions/_work/proof-conversion/proof-conversion/src/groth/adcd3_vk_regression.spec.ts
  73:27  error  '_' is assigned a value but never used  @typescript-eslint/no-unused-vars
  78:22  error  '_' is assigned a value but never used  @typescript-eslint/no-unused-vars
  83:22  error  '_' is assigned a value but never used  @typescript-eslint/no-unused-vars
  88:20  error  '_' is assigned a value but never used  @typescript-eslint/no-unused-vars

/home/runner/actions/_work/proof-conversion/proof-conversion/src/groth/recursion/18fa3_regression.spec.ts
  27:14  error  Unexpected any. Specify a different type  @typescript-eslint/no-explicit-any

/home/runner/actions/_work/proof-conversion/proof-conversion/src/groth/recursion/vendor_branch_regression.spec.ts
  30:17  error  Unexpected any. Specify a different type  @typescript-eslint/no-explicit-any
  31:19  error  Unexpected any. Specify a different type  @typescript-eslint/no-explicit-any

/home/runner/actions/_work/proof-conversion/proof-conversion/src/plonk/recursion/witness_tracker.ts
  29:10  error  'G2Line' is defined but never used  @typescript-eslint/no-unused-vars

/home/runner/actions/_work/proof-conversion/proof-conversion/src/risc0_control_id_v3.0.6.json
  0:0  warning  File ignored because no matching configuration was supplied

/home/runner/actions/_work/proof-conversion/proof-conversion/src/sha/sha_hash.ts
  1:33  error  'Field' is defined but never used     @typescript-eslint/no-unused-vars
  1:48  error  'Provable' is defined but never used  @typescript-eslint/no-unused-vars

/home/runner/actions/_work/proof-conversion/proof-conversion/src/sp1/e2e_plonk.spec.ts
  2:42  error  'Poseidon' is defined but never used  @typescript-eslint/no-unused-vars
  2:52  error  'Provable' is defined but never used  @typescript-eslint/no-unused-vars

/home/runner/actions/_work/proof-conversion/proof-conversion/src/sp1_vk_root_v6.1.0.json
  0:0  warning  File ignored because no matching configuration was supplied

✖ 18 problems (16 errors, 2 warnings)

Unit Tests - SKIPPED

Type: Info

Message: test:unit script not found


Actionable Insights

  • Add unit tests: "test:unit": "for file in $(find . -name '*.unit.spec.ts'); do npm run test -- \"$file\" || exit 1; done"
  • Add integration tests: "test:integration": "for file in $(find . -name '*.integration.spec.ts'); do npm run test -- \"$file\" || exit 1; done"
  • Auto-fix formatting: npx prettier --write "**/*.{ts,js,json,md}"
  • Linting Errors: Fix the linting errors shown above and run npm run lint locally to verify.

Configuration

Quality gate configured via environment variables.

Check Enabled Required
Dependencies true true
Build true true
Scripts true false
npm audit true true (level: moderate)
Prettier true false (dep: prettier)
Linter true false (dep: eslint)
Unit Tests true false

Note: Integration and E2E tests are checked for existence but run in CI/CD pipeline.

@jk89
jk89 merged commit 4015a64 into build Sep 25, 2026
3 checks passed
@noriBot-hub

Copy link
Copy Markdown

🔨 Build started for proof-conversion

Commit: 4015a642812b962f2e62a6e9c7e0dac6a59b38a6
Workflow: View run details

@noriBot-hub

Copy link
Copy Markdown

✅ Build succeeded for proof-conversion

Commit: 4015a642812b962f2e62a6e9c7e0dac6a59b38a6
Workflow: View run details

@noriBot-hub

Copy link
Copy Markdown

🔨 Dispatch build started for proof-conversion-nori

Proof Conversion Version: 0.8.30
Build ID: proof-conversion-70-36131698531-16
Workflow: View run details

@noriBot-hub

Copy link
Copy Markdown

✅ Dispatch build succeeded for proof-conversion-nori

Proof Conversion Version: 0.8.30
Build ID: proof-conversion-70-36131698531-16
Workflow: View run details

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants