7 Commits
Author SHA1 Message Date
pinkforest e9159ac5f7 fix: Docs repo
Continuous integration / main (push) Successful in 2m17s
2023-03-27 22:13:22 +11:00
pinkforest 49cdbfff23 chore: Update dist 2023-03-27 21:47:11 +11:00
pinkforest 27d7cd3d63 fix: Use rest client for reporter 2023-03-27 21:46:22 +11:00
pinkforest bc91a32ed8 chore: Bump to node16 2023-03-27 20:38:01 +11:00
pinkforest(she/her)andDirk Stolle 139ab94e83 chore: Bump deps (#7)
* chore: Dependency bumps

Co-authored-by: Dirk Stolle <striezel-dev@web.de>

* fix stuff

* fix more stuff

* patch lock

* Node 16

---------

Co-authored-by: Dirk Stolle <striezel-dev@web.de>
2023-03-27 20:17:23 +11:00
pinkforest(she/her) 71526086eb Fix CI without token (#6) 2023-03-26 05:09:09 +11:00
Dirk Stolle 6ef0fcd2dd Update readme and changelog for #1 (#3)
Dates for the releases in the changelog are taken from the non-
squashed commits of <https://github.com/rustsec/audit-check/pull/1>.
2023-03-14 03:14:31 +11:00
13 changed files with 19684 additions and 3589 deletions
+3 -9
View File
@@ -6,16 +6,10 @@ jobs:
main: main:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Create npm configuration - uses: actions/checkout@v3
run: echo "//npm.pkg.github.com/:_authToken=${token}" >> ~/.npmrc - uses: actions/setup-node@v3
env:
token: ${{ secrets.GITHUB_TOKEN }}
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with: with:
node-version-file: '.nvmrc' node-version: 16
cache: 'npm'
- run: npm ci - run: npm ci
# octokit types problem ? # octokit types problem ?
# - run: npm run lint # - run: npm run lint
+1 -1
View File
@@ -1 +1 @@
@clechasseur:registry=https://npm.pkg.github.com @actions-rs:registry=https://npm.pkg.github.com
+1 -1
View File
@@ -1 +1 @@
v20 v16
-12
View File
@@ -5,18 +5,6 @@ All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
## [1.4.1] - 2023-04-04
### Fixed
- Corrected reporting on `unsound` and `notice` informationals
## [1.4.0] - 2023-04-04
### Fixed
- Reflect change to enable warning on `unsound` and `notice` informationals
## [1.3.2] - 2023-03-13 ## [1.3.2] - 2023-03-13
### Changed ### Changed
+6 -46
View File
@@ -1,6 +1,7 @@
# Rust `audit-check` Action # Rust `audit-check` Action
![MIT licensed](https://img.shields.io/badge/license-MIT-blue.svg) ![MIT licensed](https://img.shields.io/badge/license-MIT-blue.svg)
[![Gitter](https://badges.gitter.im/actions-rs/community.svg)](https://gitter.im/actions-rs/community)
> Security vulnerabilities audit > Security vulnerabilities audit
@@ -26,8 +27,8 @@ jobs:
security_audit: security_audit:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v3
- uses: rustsec/audit-check@v2.0.0 - uses: rustsec/audit-check@v1
with: with:
token: ${{ secrets.GITHUB_TOKEN }} token: ${{ secrets.GITHUB_TOKEN }}
``` ```
@@ -36,33 +37,13 @@ It is recommended to add the `paths:` section into the workflow file,
as it would effectively speed up the CI pipeline, since the audit process as it would effectively speed up the CI pipeline, since the audit process
will not be performed if no dependencies were changed. will not be performed if no dependencies were changed.
In case of any security advisories found, [status check](https://help.github.com/en/articles/about-status-checks) In case of any security advisories found, [status check](https://help.github.com/en/articles/about-status-checks)
created by this Action will be marked as "failed".\ created by this Action will be marked as "failed".\
Note that informational advisories are not affecting the check status. Note that informational advisories are not affecting the check status.
![Check screenshot](.github/check_screenshot.png) ![Check screenshot](.github/check_screenshot.png)
#### Granular Permissions
These are the typically used permissions:
```yaml
name: 'rust-audit-check'
github-token:
action-input:
input: token
is-default: false
permissions:
issues: write
issues-reason: to create issues
checks: write
checks-reason: to create check
```
This action only raises issues when it's triggered from a `cron` scheduled workflow or on manual `workflow_dispatch`
When running the action as scheduled it will crate issues but e.g. in PR / push fails the action.
#### Limitations #### Limitations
Due to [token permissions](https://help.github.com/en/articles/virtual-environments-for-github-actions#token-permissions), Due to [token permissions](https://help.github.com/en/articles/virtual-environments-for-github-actions#token-permissions),
@@ -85,8 +66,8 @@ jobs:
audit: audit:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v3
- uses: rustsec/audit-check@v2.0.0 - uses: actions-rs/audit-check@v1
with: with:
token: ${{ secrets.GITHUB_TOKEN }} token: ${{ secrets.GITHUB_TOKEN }}
``` ```
@@ -103,26 +84,5 @@ For each new advisory (including informal) an issue will be created:
| ------------| -------- | ---------------------------------------------------------------------------| ------ | --------| | ------------| -------- | ---------------------------------------------------------------------------| ------ | --------|
| `token` | ✓ | [GitHub token], usually a `${{ secrets.GITHUB_TOKEN }}` | string | | | `token` | ✓ | [GitHub token], usually a `${{ secrets.GITHUB_TOKEN }}` | string | |
| `ignore` | | Comma-separated list of advisory ids to ignore | string | | | `ignore` | | Comma-separated list of advisory ids to ignore | string | |
| `working-directory`| | The directory of the Cargo.toml / Cargo.lock files to scan. | string | `.` |
[GitHub token]: https://help.github.com/en/actions/configuring-and-managing-workflows/authenticating-with-the-github_token [GitHub token]: https://help.github.com/en/actions/configuring-and-managing-workflows/authenticating-with-the-github_token
## Contribute
### Setting up npm login
This repo uses some npm packages hosted on github.
To be able to pull these you need to:
1. Under <https://github.com/settings/tokens> - create a `personal access token (classic)` with `read:packages` scope
2. Authenticate to the github npm registry
```sh
npm login --scope=@clechasseur --auth-type=legacy --registry=https://npm.pkg.github.com
```
```txt
Username = Github Username
Password = Token
```
+1 -5
View File
@@ -11,11 +11,7 @@ inputs:
ignore: ignore:
description: Comma-separated list of advisory ids to ignore description: Comma-separated list of advisory ids to ignore
required: false required: false
working-directory:
description: The directory of the Cargo.toml / Cargo.lock files to scan.
required: false
default: .
runs: runs:
using: 'node20' using: 'node16'
main: 'dist/index.js' main: 'dist/index.js'
Vendored Executable
BIN
View File
Binary file not shown.
+1 -3
View File
File diff suppressed because one or more lines are too long
+19636 -3439
View File
File diff suppressed because it is too large Load Diff
+22 -20
View File
@@ -1,6 +1,6 @@
{ {
"name": "rust-audit-check", "name": "rust-audit-check",
"version": "2.0.0", "version": "1.3.2",
"private": false, "private": false,
"description": "Security audit for security vulnerabilities", "description": "Security audit for security vulnerabilities",
"main": "lib/main.js", "main": "lib/main.js",
@@ -18,7 +18,7 @@
}, },
"repository": { "repository": {
"type": "git", "type": "git",
"url": "github:rustsec/audit-check" "url": "git+https://github.com/actions-rs/audit.git"
}, },
"keywords": [ "keywords": [
"actions", "actions",
@@ -31,27 +31,29 @@
"author": "actions-rs", "author": "actions-rs",
"license": "MIT", "license": "MIT",
"bugs": { "bugs": {
"url": "https://github.com/rustsec/audit-check/issues" "url": "https://github.com/actions-rs/audit-check/issues"
}, },
"dependencies": { "dependencies": {
"@actions/core": "^1.11.1", "@rinse-repeat/actions-rs-core": "0.1.8",
"@actions/github": "^6.0.1", "@actions/core": "^1.2.6",
"@clechasseur/rs-actions-core": "^3.0.5", "@actions/github": "^5.1.0",
"nunjucks": "^3.2.4" "npm-check-updates": "^16.8.0",
"nunjucks": "^3.2.3"
}, },
"devDependencies": { "devDependencies": {
"@types/jest": "^29.5.12", "@typescript-eslint/eslint-plugin": "^5.56.0",
"@types/node": "^20.11.17", "ts-node": "^10.9.1",
"@typescript-eslint/eslint-plugin": "^6.21.0", "@typescript-eslint/parser": "^5.56.0",
"@typescript-eslint/parser": "^6.21.0", "eslint": "^8.36.0",
"@vercel/ncc": "0.38.1", "eslint-config-prettier": "^6.11.0",
"eslint": "^8.56.0", "eslint-plugin-prettier": "^3.1.3",
"eslint-config-prettier": "^9.1.0", "@types/jest": "^26.0.1",
"eslint-plugin-prettier": "^5.1.3", "@types/node": "^16.11.7",
"jest": "^29.7.0", "@vincentriemer/ncc": "^0.20.5",
"prettier": "^3.2.5", "jest": "^26.0.1",
"ts-jest": "^29.1.2", "jest-circus": "^26.0.1",
"ts-node": "^10.9.2", "ts-jest": "^26.0.1",
"typescript": "^5.3.3" "typescript": "^3.8.3",
"prettier": "^2.0.5"
} }
} }
+3 -4
View File
@@ -2,19 +2,18 @@
* Parse action input into a some proper thing. * Parse action input into a some proper thing.
*/ */
import { input } from '@clechasseur/rs-actions-core'; import { input } from '@rinse-repeat/actions-rs-core';
import { getInputList } from '@rinse-repeat/actions-rs-core/dist/input';
// Parsed action input // Parsed action input
export interface Input { export interface Input {
token: string; token: string;
ignore: string[]; ignore: string[];
workingDirectory: string;
} }
export function get(): Input { export function get(): Input {
return { return {
token: input.getInput('token', { required: true }), token: input.getInput('token', { required: true }),
ignore: input.getInputList('ignore', { required: false }), ignore: getInputList('ignore', { required: false }),
workingDirectory: input.getInput('working-directory', { required: false }) ?? '.',
}; };
} }
+7 -18
View File
@@ -1,10 +1,10 @@
import * as os from 'os';
import * as process from 'process'; import * as process from 'process';
import * as os from 'os';
import * as core from '@actions/core'; import * as core from '@actions/core';
import * as github from '@actions/github'; import * as github from '@actions/github';
import { Cargo } from '@clechasseur/rs-actions-core'; import { Cargo } from '@rinse-repeat/actions-rs-core';
import * as input from './input'; import * as input from './input';
import * as interfaces from './interfaces'; import * as interfaces from './interfaces';
@@ -12,11 +12,12 @@ import * as reporter from './reporter';
async function getData( async function getData(
ignore: string[] | undefined, ignore: string[] | undefined,
workingDirectory: string,
): Promise<interfaces.Report> { ): Promise<interfaces.Report> {
const cargo = await Cargo.get(); const cargo = await Cargo.get();
await cargo.findOrInstall('cargo-audit'); await cargo.findOrInstall('cargo-audit');
await cargo.call(['generate-lockfile']);
let stdout = ''; let stdout = '';
try { try {
core.startGroup('Calling cargo-audit (JSON output)'); core.startGroup('Calling cargo-audit (JSON output)');
@@ -25,7 +26,6 @@ async function getData(
commandArray.push('--ignore', item); commandArray.push('--ignore', item);
} }
commandArray.push('--json'); commandArray.push('--json');
commandArray.push('--file', `${workingDirectory}/Cargo.lock`);
await cargo.call(commandArray, { await cargo.call(commandArray, {
ignoreReturnCode: true, ignoreReturnCode: true,
listeners: { listeners: {
@@ -46,17 +46,9 @@ async function getData(
return JSON.parse(stdout); return JSON.parse(stdout);
} }
function removeTrailingSlash(str) {
if (str[str.length - 1] === '/') {
return str.substr(0, str.length - 1);
}
return str;
}
export async function run(actionInput: input.Input): Promise<void> { export async function run(actionInput: input.Input): Promise<void> {
const ignore = actionInput.ignore; const ignore = actionInput.ignore;
const workingDirectory = removeTrailingSlash(actionInput.workingDirectory); const report = await getData(ignore);
const report = await getData(ignore, workingDirectory);
let shouldReport = false; let shouldReport = false;
if (!report.vulnerabilities.found) { if (!report.vulnerabilities.found) {
core.info('No vulnerabilities were found'); core.info('No vulnerabilities were found');
@@ -90,10 +82,7 @@ export async function run(actionInput: input.Input): Promise<void> {
// const octokit = github.getOctokit(actionInput.token, {userAgent: USER_AGENT}); // const octokit = github.getOctokit(actionInput.token, {userAgent: USER_AGENT});
const advisories = report.vulnerabilities.list; const advisories = report.vulnerabilities.list;
if ( if (github.context.eventName == 'schedule') {
github.context.eventName == 'schedule' ||
github.context.eventName == 'workflow_dispatch'
) {
core.debug( core.debug(
'Action was triggered on a schedule event, creating an Issues report', 'Action was triggered on a schedule event, creating an Issues report',
); );
@@ -111,7 +100,7 @@ async function main(): Promise<void> {
const actionInput = input.get(); const actionInput = input.get();
await run(actionInput); await run(actionInput);
} catch (error) { } catch (error) {
core.setFailed((error as Error).message); core.setFailed(error.message);
} }
return; return;
+3 -31
View File
@@ -4,7 +4,7 @@ import * as core from '@actions/core';
import * as github from '@actions/github'; import * as github from '@actions/github';
import * as nunjucks from 'nunjucks'; import * as nunjucks from 'nunjucks';
import { checks } from '@clechasseur/rs-actions-core'; import { checks } from '@rinse-repeat/actions-rs-core';
import * as interfaces from './interfaces'; import * as interfaces from './interfaces';
import * as templates from './templates'; import * as templates from './templates';
@@ -15,7 +15,6 @@ interface Stats {
critical: number; critical: number;
notices: number; notices: number;
unmaintained: number; unmaintained: number;
unsound: number;
other: number; other: number;
} }
@@ -38,20 +37,6 @@ function makeReport(
}); });
break; break;
case 'unsound':
preparedWarnings.push({
advisory: warning.advisory,
package: warning.package,
});
break;
case 'notice':
preparedWarnings.push({
advisory: warning.advisory,
package: warning.package,
});
break;
case 'informational': case 'informational':
preparedWarnings.push({ preparedWarnings.push({
advisory: warning.advisory, advisory: warning.advisory,
@@ -90,7 +75,6 @@ function getStats(
let critical = 0; let critical = 0;
let notices = 0; let notices = 0;
let unmaintained = 0; let unmaintained = 0;
let unsound = 0;
let other = 0; let other = 0;
for (const vulnerability of vulnerabilities) { for (const vulnerability of vulnerabilities) {
switch (vulnerability.advisory.informational) { switch (vulnerability.advisory.informational) {
@@ -100,9 +84,6 @@ function getStats(
case 'unmaintained': case 'unmaintained':
unmaintained += 1; unmaintained += 1;
break; break;
case 'unsound':
unsound += 1;
break;
case null: case null:
critical += 1; critical += 1;
break; break;
@@ -118,10 +99,6 @@ function getStats(
unmaintained += 1; unmaintained += 1;
break; break;
case 'unsound':
unsound += 1;
break;
default: default:
// Both yanked and informational types of kind // Both yanked and informational types of kind
other += 1; other += 1;
@@ -133,7 +110,6 @@ function getStats(
critical: critical, critical: critical,
notices: notices, notices: notices,
unmaintained: unmaintained, unmaintained: unmaintained,
unsound: unsound,
other: other, other: other,
}; };
} }
@@ -142,7 +118,8 @@ function getSummary(stats: Stats): string {
const blocks: string[] = []; const blocks: string[] = [];
if (stats.critical > 0) { if (stats.critical > 0) {
blocks.push(`${stats.critical} advisories`); // TODO: Plural
blocks.push(`${stats.critical} advisory(ies)`);
} }
if (stats.notices > 0) { if (stats.notices > 0) {
blocks.push(`${stats.notices} notice${plural(stats.notices)}`); blocks.push(`${stats.notices} notice${plural(stats.notices)}`);
@@ -150,9 +127,6 @@ function getSummary(stats: Stats): string {
if (stats.unmaintained > 0) { if (stats.unmaintained > 0) {
blocks.push(`${stats.unmaintained} unmaintained`); blocks.push(`${stats.unmaintained} unmaintained`);
} }
if (stats.unsound > 0) {
blocks.push(`${stats.unsound} unsound`);
}
if (stats.other > 0) { if (stats.other > 0) {
blocks.push(`${stats.other} other`); blocks.push(`${stats.other} other`);
} }
@@ -287,8 +261,6 @@ export async function reportIssues(
for (const warning of warnings) { for (const warning of warnings) {
let advisory: interfaces.Advisory; let advisory: interfaces.Advisory;
switch (warning.kind) { switch (warning.kind) {
case 'unsound':
case 'notice':
case 'unmaintained': case 'unmaintained':
case 'informational': case 'informational':
advisory = warning.advisory; advisory = warning.advisory;