From a3841eb17280de9522032b58541ba797d29c0170 Mon Sep 17 00:00:00 2001 From: grloper Date: Fri, 9 Oct 2026 21:31:09 +0300 Subject: [PATCH 1/2] ci: add cargo-audit and cargo-deny supply-chain workflow --- .github/workflows/supply-chain.yml | 30 ++++++++++++++++++++++++++++++ deny.toml | 16 ++++++++++++++++ 2 files changed, 46 insertions(+) create mode 100644 .github/workflows/supply-chain.yml create mode 100644 deny.toml diff --git a/.github/workflows/supply-chain.yml b/.github/workflows/supply-chain.yml new file mode 100644 index 0000000..7e95b8a --- /dev/null +++ b/.github/workflows/supply-chain.yml @@ -0,0 +1,30 @@ +name: supply-chain + +on: + pull_request: + paths: ["Cargo.toml", "Cargo.lock", "deny.toml", ".github/workflows/supply-chain.yml"] + push: + branches: [main] + schedule: + - cron: "17 4 * * 1" + workflow_dispatch: + +permissions: + contents: read + +jobs: + audit: + runs-on: ubuntu-22.04 + timeout-minutes: 30 + steps: + - uses: actions/checkout@v4 + - name: Install stable Rust + run: | + rustup toolchain install stable --profile minimal + rustup default stable + - name: Install cargo-audit and cargo-deny + run: cargo install --locked cargo-audit cargo-deny + - name: cargo audit (RustSec advisories) + run: cargo audit + - name: cargo deny (advisories, licenses, bans, sources) + run: cargo deny check diff --git a/deny.toml b/deny.toml new file mode 100644 index 0000000..08b9483 --- /dev/null +++ b/deny.toml @@ -0,0 +1,16 @@ +# cargo-deny policy. Kept deliberately minimal; tighten as the project matures. +[advisories] +version = 2 +yanked = "deny" + +[licenses] +version = 2 +allow = ["MIT", "Apache-2.0"] + +[bans] +multiple-versions = "warn" +wildcards = "deny" + +[sources] +unknown-registry = "deny" +unknown-git = "deny" From 2bb82885e4a4c71898f0c4d2da23f30f89d34a7f Mon Sep 17 00:00:00 2001 From: grloper Date: Fri, 9 Oct 2026 21:53:48 +0300 Subject: [PATCH 2/2] ci(supply-chain): widen license allow-list, document bans policy, pin and cache tools --- .github/workflows/supply-chain.yml | 26 ++++++++++++++++++++++++-- deny.toml | 21 ++++++++++++++++++++- 2 files changed, 44 insertions(+), 3 deletions(-) diff --git a/.github/workflows/supply-chain.yml b/.github/workflows/supply-chain.yml index 7e95b8a..9f8d5ce 100644 --- a/.github/workflows/supply-chain.yml +++ b/.github/workflows/supply-chain.yml @@ -12,6 +12,12 @@ on: permissions: contents: read +env: + # Pinned tool versions (latest releases at the time of writing; both install + # with --locked on current stable). Bump deliberately. + CARGO_AUDIT_VERSION: "0.22.2" + CARGO_DENY_VERSION: "0.20.2" + jobs: audit: runs-on: ubuntu-22.04 @@ -22,8 +28,24 @@ jobs: run: | rustup toolchain install stable --profile minimal rustup default stable - - name: Install cargo-audit and cargo-deny - run: cargo install --locked cargo-audit cargo-deny + - name: Cache installed cargo tools + id: tools-cache + uses: actions/cache@v4 + with: + path: ~/.cargo/bin/cargo-audit + key: cargo-audit-${{ env.CARGO_AUDIT_VERSION }}-${{ runner.os }}-${{ runner.arch }} + - name: Cache cargo-deny + id: deny-cache + uses: actions/cache@v4 + with: + path: ~/.cargo/bin/cargo-deny + key: cargo-deny-${{ env.CARGO_DENY_VERSION }}-${{ runner.os }}-${{ runner.arch }} + - name: Install cargo-audit (pinned) + if: steps.tools-cache.outputs.cache-hit != 'true' + run: cargo install --locked cargo-audit --version "$CARGO_AUDIT_VERSION" + - name: Install cargo-deny (pinned) + if: steps.deny-cache.outputs.cache-hit != 'true' + run: cargo install --locked cargo-deny --version "$CARGO_DENY_VERSION" - name: cargo audit (RustSec advisories) run: cargo audit - name: cargo deny (advisories, licenses, bans, sources) diff --git a/deny.toml b/deny.toml index 08b9483..fef215f 100644 --- a/deny.toml +++ b/deny.toml @@ -5,11 +5,30 @@ yanked = "deny" [licenses] version = 2 -allow = ["MIT", "Apache-2.0"] +# Allow-list intentionally broader than the current tree; do not warn on unused entries. +unused-allowed-license = "allow" +# Permissive licenses only; extend deliberately (copyleft is not allowed). +allow = [ + "MIT", + "Apache-2.0", + "Unicode-3.0", + "Unicode-DFS-2016", + "BSD-2-Clause", + "BSD-3-Clause", + "ISC", + "Zlib", +] [bans] +# Duplicate crate versions are common in transitive trees (e.g. across a +# dependabot bump) and are not a security problem by themselves: report them +# as warnings (visible in CI logs) but do not fail the build. multiple-versions = "warn" +# Wildcard version requirements ("*") in our own manifest are denied: every +# dependency must have a bounded requirement so builds are reviewable. wildcards = "deny" +# Path dependencies of the workspace itself are exempt. +allow-wildcard-paths = true [sources] unknown-registry = "deny"