Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -467,7 +467,7 @@ jobs:
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2

- name: Build with the declared MSRV
run: cargo build --all-targets --all-features
run: cargo +${{ steps.msrv.outputs.version }} build --all-targets --all-features

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority high security likely

Pass the MSRV through a quoted environment variable

steps.msrv.outputs.version is derived from Cargo.toml in the checked-out repository and is interpolated directly into a shell command. A crafted value that reaches this output could alter the command executed by the runner. Put the output in an environment variable and invoke Cargo with the quoted variable, for example cargo +"$MSRV" build ....


Additional critique observation

priority medium confident

Pass the MSRV through the environment before invoking the shell

[RULE] shell-interpolation

steps.msrv.outputs.version is derived from the repository's Cargo.toml, which is untrusted in pull-request CI, and is interpolated directly into run. Keep the expression in an env value and invoke cargo +"$MSRV" ... so repository-controlled data is not expanded as shell source.

[RULE] untrusted-shell-interpolation ·

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium security confident

Pass the MSRV through the environment before invoking the shell

The MSRV output is currently expanded into the run script itself. Environment passing keeps the value as data and prevents shell parsing of repository-controlled content; define an MSRV step environment variable from the output and use "+$MSRV" in the command.

[RULE] shell-injection ·


supply-chain:
name: Supply chain
Expand Down
3 changes: 3 additions & 0 deletions rust-toolchain.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
[toolchain]
channel = "1.96.1"
profile = "minimal"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Install the components required by repository checks

A minimal rustup profile does not install rustfmt or clippy, so developers using this rust-toolchain.toml will fail the documented cargo fmt and cargo clippy commands with missing-component errors. Add both components to the toolchain configuration.

[RULE] missing-toolchain-components ·

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium security confident

Install the components required by repository checks

The minimal rustup profile does not install rustfmt, clippy, or llvm-tools-preview, while the repository's CI checks require these components. Add them explicitly so a fresh checkout using this toolchain file can run the documented checks.

[RULE] missing-toolchain-components ·

Loading