csaf_ndaal:ndaal-sa-2026-646

csaf_ndaal
Description

grundschutz-oscal-viewer 1.6.59 (the offline viewer for the BSI Grundschutz++ OSCAL catalog) is a QUALITY-INFRASTRUCTURE release. It contains no user-facing change: the viewer behaves exactly as 1.6.58 did, and no vulnerability is fixed or introduced. It is announced for supply-chain transparency because a new version is on crates.io and a new set of signed binaries is on GitLab.

Timeline
Published
2026-09-17 00:00 UTC
Last Modified
2026-09-17
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "$schema": "https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json",
  "document": {
    "category": "csaf_informational_advisory",
    "csaf_version": "2.1",
    "distribution": {
      "tlp": {
        "label": "CLEAR"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "grundschutz-oscal-viewer 1.6.59 (the offline viewer for the BSI Grundschutz++ OSCAL catalog) is a QUALITY-INFRASTRUCTURE release. It contains no user-facing change: the viewer behaves exactly as 1.6.58 did, and no vulnerability is fixed or introduced. It is announced for supply-chain transparency because a new version is on crates.io and a new set of signed binaries is on GitLab.",
        "title": "Summary"
      },
      {
        "category": "description",
        "text": "Changelog (1.6.59):\n\nNo user-facing change. This release is entirely test coverage and\nquality-gate infrastructure; the viewer behaves exactly as 1.6.58 did.\n\n### Added\n\n- cargo_rapx gate — MIR-level memory-safety analysis.\n  tests/scripts/test_cargo_rapx.sh, with its bats sibling and README,\n  runs the RAPx static analyzer for use-after-free, double-free, dangling\n  pointers and leaks inside unsafe. On this crate it reports nothing by\n  construction: the library is #![forbid(unsafe_code)], so the gate\n  records that absence rather than discovering anything.\n- A Git pre-commit hook at .githooks/pre-commit, from\n  skills/rust-pre-commit, activated with a WORKTREE-SCOPED\n  core.hooksPath. It runs typos, rustfmt, clippy, the test suites,\n  doctests, cargo doc and rust-doctor before a commit is created. The\n  four git-lfs hooks are carried into .githooks/ because\n  core.hooksPath replaces .git/hooks wholesale and would otherwise\n  disable them silently. The primary checkout still uses .git/hooks;\n  activate it there with git config core.hooksPath .githooks.\n- Four property tests closing the coverage gaps left by the\n  whole-tree audit: parameter substitution, dump-file listing order,\n  from_parts language resolution across crumbled cookie headers, and\n  framework display defaults for unknown slugs.\n\n### Changed\n\n- Every #[allow] in first-party code carries reason = \"...\" — 105\n  sites across 73 files, taking rust-doctor's\n  unreasoned_allow_attribute from 129 occurrences to zero. The reasons\n  are not new: nearly every site already carried a // WHY: comment\n  saying exactly this, in a form no tool could check.\n- The rust-doctor gate scores the crate, not the vendored skills/\n  tree. rust-doctor 0.7.0 has no path-exclusion mechanism, so\n  scanning the repo root also judged 20,085 vendored third-party files\n  whose security documentation legitimately contains example AWS keys —\n  50 hardcoded_credential findings, one of them a P1 that capped the\n  score at 65. The gate now scans a copy-on-write clone with skills/\n  removed. Measured, both scans complete: 48/100 \"Critical\" for the repo\n  root versus 79/100 \"Great\" for the crate alone, no ceiling, zero\n  credential findings, security dimension 100.\n- .typos.toml scopes the spell check to first-party text — the\n  vendored skills/ tree, the embedded catalog and crosswalk CSVs, the\n  non-English README mirrors, the 49-language translation corpus and\n  vendored illustrations. Its globs are /-prefixed because typos\n  matches them against the path as given, so an unprefixed glob applies\n  to typos . but silently not to the absolute path a hook passes.\n\n### Fixed\n\n- Two mutation gaps in the annotation store's dump/restore path.\n  ensure_restored_schema's missing-table check was only exercised by a\n  single-table dump, which both the correct predicate and its inversion\n  reject; and the dump round-trip property asserted only is_ok(), which\n  a dump carrying the schema and none of the rows also satisfies. Both\n  now fail against the mutant. The module's mutation score goes from\n  23/24 to 24/24 on testable mutants.\n- Three clippy::indexing_slicing denials introduced with the\n  property tests, which cargo test cannot see and which left\n  cargo clippy --all-targets -- -D warnings red on the committed tree.\n- Two genuine misspellings in the gate scripts, found while scoping\n  the spell check. The other 109 findings were false positives that must\n  NOT be \"corrected\" — bats fixtures asserting a literal string,\n  deliberate glob prefixes, comments quoting a misspelling on purpose,\n  Latin interface text and crate names — so typos -w would have broken\n  tests here.\n\n### Known\n\n- dependencies scores 11/100. Ten crates resolve at two\n  incompatible major versions, every one of them through\n  dev-dependencies rather than the shipped binary. The io-lifetimes\n  duplicate is upstream-blocked: fs-set-times has no release using\n  io-lifetimes 3.x, and cap-std is already at its latest version.\n- The pre-commit hook's rust-doctor step does not block. rust-doctor\n  exposes no way to raise its internal time budget, and its structural\n  analysis stops at that budget under load — immediately after the hook\n  has run the whole test suite — reporting \"Gate not evaluated\" for a\n  commit that passes on an idle machine. An incomplete scan is therefore\n  reported loudly rather than failing the commit; a scan that completes\n  and finds error-level issues still blocks.",
        "title": "Description"
      },
      {
        "category": "details",
        "text": "crates.io: grundschutz-oscal-viewer 1.6.59 is live and installable — cargo install grundschutz-oscal-viewer.\n\nGitLab release v1.6.59 carries six cross-compiled binaries (x86_64/aarch64 × unknown-linux-musl, apple-darwin, and pc-windows-gnu/gnullvm), each accompanied by five checksum sidecars from four independent hash constructions: .sha-256 and .sha-512 (SHA-2, Merkle–Damgård), .sha3-512 (Keccak sponge), .blake3-512 (BLAKE3 tree hash) and .shake256-512 (FIPS-202 extendable-output function) — 36 assets in total. Verify a download against at least two families before trusting it.",
        "title": "Release artefacts"
      },
      {
        "category": "general",
        "text": "Recommended action for downstream consumers: OPTIONAL. Upgrade to 1.6.59 at convenience — cargo install grundschutz-oscal-viewer — or stay on 1.6.58. Because 1.6.59 changes no runtime behaviour and fixes no vulnerability, there is no security reason to upgrade and no reason to delay. Operators who pin a version for reproducibility may safely skip this release.",
        "title": "Recommended action"
      },
      {
        "category": "other",
        "text": "Disposition: informational — a quality-infrastructure release announcement. No CVE is assigned, no vulnerability is fixed, and no product is affected. The changes are test coverage and CI gates: two mutation gaps closed in the store's dump/restore path (module mutation score 23/24 → 24/24 on testable mutants), four property tests, a RAPx MIR-level memory-safety gate (a standing no-op here, as the library is #![forbid(unsafe_code)]), a pre-commit hook, and 105 #[allow] attributes given machine-readable reasons. Two known limitations are recorded in the changelog's Known section rather than omitted: the dependencies dimension scores 11/100 on dev-dependency duplicates that never ship in the binary, and the pre-commit hook's rust-doctor step does not block on an incomplete scan.",
        "title": "Disposition"
      },
      {
        "category": "legal_disclaimer",
        "text": "THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY. ndaal Gesellschaft fuer Sicherheit in der Informationstechnik mbH & Co KG DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS INFORMATION INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS."
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "security@ndaal.eu",
      "issuing_authority": "ndaal Gesellschaft für Sicherheit in der Informationstechnik mbH & Co KG Security Team",
      "name": "ndaal Gesellschaft für Sicherheit in der Informationstechnik mbH & Co KG",
      "namespace": "https://ndaal.eu/csaf"
    },
    "references": [
      {
        "category": "self",
        "summary": "This advisory in CSAF 2.1 format",
        "url": "https://gitlab.com/vPierre/ndaal_public_nvulnlookup/-/raw/main/csaf/2026/646/ndaal-sa-2026-646.json"
      },
      {
        "category": "external",
        "summary": "grundschutz-oscal-viewer GitLab release v1.6.59 (six binaries + five checksum sidecars each)",
        "url": "https://gitlab.com/vPierre/ndaal_public_bsi_grundschutz_oscal_viewer/-/releases/v1.6.59"
      },
      {
        "category": "external",
        "summary": "grundschutz-oscal-viewer 1.6.59 on crates.io",
        "url": "https://crates.io/crates/grundschutz-oscal-viewer/1.6.59"
      },
      {
        "category": "external",
        "summary": "ndaal_public_bsi_grundschutz_oscal_viewer repository",
        "url": "https://gitlab.com/vPierre/ndaal_public_bsi_grundschutz_oscal_viewer"
      },
      {
        "category": "external",
        "summary": "grundschutz-oscal-viewer CHANGELOG (1.6.59 entry)",
        "url": "https://gitlab.com/vPierre/ndaal_public_bsi_grundschutz_oscal_viewer/-/blob/main/CHANGELOG.md"
      },
      {
        "category": "external",
        "summary": "Preceding release advisory: ndaal-sa-2026-509 (grundschutz-oscal-viewer 1.6.58)",
        "url": "https://gitlab.com/vPierre/ndaal_public_nvulnlookup/-/raw/main/csaf/2026/509/ndaal-sa-2026-509.json"
      }
    ],
    "title": "ndaal Informational Advisory: release of grundschutz-oscal-viewer 1.6.59 — a test-coverage and quality-gate release with NO user-facing change and NO security fix; closes two mutation gaps in the annotation store's dump/restore path, adds a pre-commit hook and a RAPx memory-safety gate, gives every #[allow] a machine-readable reason, and rescopes the rust-doctor and typos gates to first-party code; published to crates.io and as GitLab release v1.6.59 with six cross-target binaries",
    "tracking": {
      "current_release_date": "2026-09-17T00:00:00.000Z",
      "generator": {
        "engine": {
          "name": "ndaal CSAF Generator",
          "version": "1.0.0"
        }
      },
      "id": "ndaal-sa-2026-646",
      "initial_release_date": "2026-09-17T00:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-09-17T00:00:00.000Z",
          "number": "1.0.0",
          "summary": "Initial informational advisory announcing the release of grundschutz-oscal-viewer 1.6.59."
        }
      ],
      "status": "final",
      "version": "1.0.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "1.6.58",
                "product": {
                  "name": "grundschutz-oscal-viewer 1.6.58 — the prior version; functionally identical to 1.6.59 at runtime",
                  "product_id": "CSAFPID-0001",
                  "product_identification_helper": {
                    "purls": [
                      "pkg:cargo/grundschutz-oscal-viewer@1.6.58"
                    ]
                  }
                }
              },
              {
                "category": "product_version",
                "name": "1.6.59",
                "product": {
                  "name": "grundschutz-oscal-viewer 1.6.59 — this release: test coverage and quality-gate infrastructure only, with no user-facing change and no security fix",
                  "product_id": "CSAFPID-0002",
                  "product_identification_helper": {
                    "purls": [
                      "pkg:cargo/grundschutz-oscal-viewer@1.6.59"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "grundschutz-oscal-viewer"
          }
        ],
        "category": "vendor",
        "name": "ndaal Gesellschaft für Sicherheit in der Informationstechnik mbH & Co KG"
      }
    ]
  }
}
View JSON API Download JSON