Skip to content

Security

Security #78

Workflow file for this run

name: Security
# Disabled: GitHub Actions budget exhausted.
# Remove the `if: false` on each job to re-enable.
on:
schedule:
# Run daily at 9am UTC
- cron: '0 9 * * *'
push:
branches: [main]
paths:
- 'Cargo.toml'
- 'Cargo.lock'
- 'deny.toml'
pull_request:
paths:
- 'Cargo.toml'
- 'Cargo.lock'
- 'deny.toml'
workflow_dispatch:
permissions:
contents: read
jobs:
audit:
name: Security Audit
runs-on: ubuntu-latest
if: false
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@v5
with:
persist-credentials: false
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
- name: Cache cargo-audit
uses: actions/cache@v5
with:
path: ~/.cargo/bin/cargo-audit
key: cargo-audit-0.20
- name: Install cargo-audit
run: |
if ! command -v cargo-audit &> /dev/null; then
cargo install cargo-audit --locked
fi
- name: Run cargo-audit
run: cargo audit --deny warnings
deny:
name: Dependency Check
runs-on: ubuntu-latest
if: false
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@v5
with:
persist-credentials: false
- name: Dependency policy (cargo-deny)
uses: EmbarkStudios/cargo-deny-action@v2
with:
manifest-path: Cargo.toml