Capabilities and resource limits
Make each host capability and execution budget an explicit choice.
Default-deny host access
Wasmd does not automatically inherit the host filesystem, environment, or network. Preview 1 offers 46 capability-based imports. A host that supplies directories, environment variables, network access, or host functions is extending the trust boundary.
Bound guest execution
Fuel, epoch deadlines, cancellation, and limits for memory, tables, stacks, and GC constrain guest execution. Memory-page limits are not a total process RSS limit. GC offers explicit bounded steps, but full collection, destruction, and allocation pressure are not hard-real-time operations.
Keep interface claims versioned
Component execution and WASI 0.2/0.3 development profiles are implemented, with distinct capability policies and acceptance reports. The published 1.0 security policy excludes Component Model and Preview 2 from its release claim. Do not equate a development feature with an expanded release security guarantee.
Verify releases and report issues
Verify checksums and release attestations against a trusted repository, workflow, tag, and source commit. Report vulnerabilities privately with the affected version, platform, minimal reproducer, and impact. Follow the repository security policy for current reporting instructions.
Based on the current repository documentation. Check your installed version and the linked acceptance records when adopting development features.
Read the Wasmd source document ↗