Skip to content

fix(ci): pin third-party actions to full commit SHAs (#201) #607

fix(ci): pin third-party actions to full commit SHAs (#201)

fix(ci): pin third-party actions to full commit SHAs (#201) #607

Workflow file for this run

# SPDX-License-Identifier: MPL-2.0

Check failure on line 1 in .github/workflows/cargo-audit.yml

View workflow run for this annotation

GitHub Actions / .github/workflows/cargo-audit.yml

Invalid workflow file

(Line: 30, Col: 9): 'with' is already defined
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
name: Security Audit
on:
push:
branches: [ main ]
pull_request:
branches: [ main ]
schedule:
- cron: '0 0 * * 0' # Weekly on Sunday
permissions:
contents: read
jobs:
audit:
name: Cargo Audit
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Checkout code
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1
with:
toolchain: v1
with:
toolchain: stable
- name: Install cargo-audit
run: cargo install cargo-audit
- name: Run cargo audit
run: cargo audit