Skip to content

ci: cargo-audit + cargo-deny supply-chain workflow - #21

Merged
grloper merged 2 commits into
mainfrom
ci/supply-chain-audit
Oct 9, 2026
Merged

grloper merged 2 commits into
mainfrom
ci/supply-chain-audit

Conversation

@grloper

@grloper grloper commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Adds deny.toml and a workflow (PR touching Cargo files, push to main, weekly cron, manual) that runs cargo audit and cargo deny check. Dependabot for cargo/github-actions is unchanged.

Changes in this revision:

  • Licenses allow-list: MIT, Apache-2.0, Unicode-3.0, Unicode-DFS-2016, BSD-2-Clause, BSD-3-Clause, ISC, Zlib (unused-allowed-license = "allow" so unused entries do not warn).
  • Bans policy documented in deny.toml: multiple-versions = "warn" (duplicates are reported, not fatal), wildcards = "deny" with allow-wildcard-paths = true.
  • Tools pinned: cargo-audit 0.22.2, cargo-deny 0.20.2 (latest on crates.io), installed with --locked and cached via actions/cache keyed on version, so reruns skip the ~3 min compile.

Verified locally (cargo-deny 0.20.2 / cargo-audit 0.22.2): cargo deny check licenses ok on this branch, and cargo deny check + cargo audit clean on the lockfiles of dependabot branches for #11 (nix 0.31.3), #12 (upload-artifact 6) and #13 (libc 0.2.190). Not merged.

@grloper
grloper merged commit 86220db into main Oct 9, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant