7 Commits
Author SHA1 Message Date
Aaron Kelbsch 26f9009348 docs: update docs
Continuous integration / main (push) Failing after 1m43s
2025-08-25 15:52:46 +02:00
Aaron Kelbsch d8774e016c feat: allow custom labels for new issues 2025-08-25 15:50:51 +02:00
Aaron Kelbsch d1a8548176 docs: update readme
Continuous integration / main (push) Failing after 51s
2025-08-25 15:41:05 +02:00
Aaron Kelbsch 4869f6bfcf feat: also write issues when manually triggered 2025-08-25 15:37:02 +02:00
Aaron Kelbsch b0356b9add chore: add missing dependencies to package json 2025-08-25 15:36:26 +02:00
Aaron Kelbsch 34d5211002 docs: add contribution info to readme 2025-08-25 15:32:31 +02:00
Aaron Kelbsch c5a5443df7 chore: update package.json 2025-08-25 15:32:21 +02:00
7 changed files with 93 additions and 59 deletions
+22 -2
View File
@@ -36,7 +36,6 @@ It is recommended to add the `paths:` section into the workflow file,
as it would effectively speed up the CI pipeline, since the audit process as it would effectively speed up the CI pipeline, since the audit process
will not be performed if no dependencies were changed. will not be performed if no dependencies were changed.
In case of any security advisories found, [status check](https://help.github.com/en/articles/about-status-checks) In case of any security advisories found, [status check](https://help.github.com/en/articles/about-status-checks)
created by this Action will be marked as "failed".\ created by this Action will be marked as "failed".\
Note that informational advisories are not affecting the check status. Note that informational advisories are not affecting the check status.
@@ -60,7 +59,7 @@ github-token:
checks-reason: to create check checks-reason: to create check
``` ```
The action does not raise issues when it is not triggered from a "cron" scheduled workflow. This action only raises issues when it's triggered from a `cron` scheduled workflow or on manual `workflow_dispatch`
When running the action as scheduled it will crate issues but e.g. in PR / push fails the action. When running the action as scheduled it will crate issues but e.g. in PR / push fails the action.
@@ -105,5 +104,26 @@ For each new advisory (including informal) an issue will be created:
| `token` | ✓ | [GitHub token], usually a `${{ secrets.GITHUB_TOKEN }}` | string | | | `token` | ✓ | [GitHub token], usually a `${{ secrets.GITHUB_TOKEN }}` | string | |
| `ignore` | | Comma-separated list of advisory ids to ignore | string | | | `ignore` | | Comma-separated list of advisory ids to ignore | string | |
| `working-directory`| | The directory of the Cargo.toml / Cargo.lock files to scan. | string | `.` | | `working-directory`| | The directory of the Cargo.toml / Cargo.lock files to scan. | string | `.` |
| `new-issue-labels` | | Comma-separated list of Labes to be added to new issues | string | `.` |
[GitHub token]: https://help.github.com/en/actions/configuring-and-managing-workflows/authenticating-with-the-github_token [GitHub token]: https://help.github.com/en/actions/configuring-and-managing-workflows/authenticating-with-the-github_token
## Contribute
### Setting up npm login
This repo uses some npm packages hosted on github.
To be able to pull these you need to:
1. Under <https://github.com/settings/tokens> - create a `personal access token (classic)` with `read:packages` scope
2. Authenticate to the github npm registry
```sh
npm login --scope=@clechasseur --auth-type=legacy --registry=https://npm.pkg.github.com
```
```txt
Username = Github Username
Password = Token
```
+3 -3
View File
File diff suppressed because one or more lines are too long
+34 -38
View File
@@ -1,14 +1,16 @@
{ {
"name": "rust-audit-check", "name": "rust-audit-check",
"version": "1.4.1", "version": "2.0.0",
"lockfileVersion": 3, "lockfileVersion": 3,
"requires": true, "requires": true,
"packages": { "packages": {
"": { "": {
"name": "rust-audit-check", "name": "rust-audit-check",
"version": "1.4.1", "version": "2.0.0",
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"@actions/core": "^1.11.1",
"@actions/github": "^6.0.1",
"@clechasseur/rs-actions-core": "^3.0.5", "@clechasseur/rs-actions-core": "^3.0.5",
"nunjucks": "^3.2.4" "nunjucks": "^3.2.4"
}, },
@@ -56,22 +58,13 @@
} }
}, },
"node_modules/@actions/core": { "node_modules/@actions/core": {
"version": "1.10.1", "version": "1.11.1",
"resolved": "https://registry.npmjs.org/@actions/core/-/core-1.10.1.tgz", "resolved": "https://registry.npmjs.org/@actions/core/-/core-1.11.1.tgz",
"integrity": "sha512-3lBR9EDAY+iYIpTnTIXmWcNbX3T2kCkAEQGIQx4NVQ0575nk2k3GRZDTPQG+vVtS2izSLmINlxXf0uLtnrTP+g==", "integrity": "sha512-hXJCSrkwfA46Vd9Z3q4cpEpHB1rL5NG04+/rbqW9d3+CSvtB1tYe8UTpAlixa1vj0m/ULglfEK2UKxMGxCxv5A==",
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"@actions/http-client": "^2.0.1", "@actions/exec": "^1.1.1",
"uuid": "^8.3.2" "@actions/http-client": "^2.0.1"
}
},
"node_modules/@actions/core/node_modules/uuid": {
"version": "8.3.2",
"resolved": "https://registry.npmjs.org/uuid/-/uuid-8.3.2.tgz",
"integrity": "sha512-+NYs2QeMWy+GWFOEm9xnn6HCDp0l7QBD7ml8zLUmJ+93Q5NF0NocErnwkTkXVFNiX3/fpC6afS8Dhb/gz7R7eg==",
"license": "MIT",
"bin": {
"uuid": "dist/bin/uuid"
} }
}, },
"node_modules/@actions/exec": { "node_modules/@actions/exec": {
@@ -84,15 +77,18 @@
} }
}, },
"node_modules/@actions/github": { "node_modules/@actions/github": {
"version": "6.0.0", "version": "6.0.1",
"resolved": "https://registry.npmjs.org/@actions/github/-/github-6.0.0.tgz", "resolved": "https://registry.npmjs.org/@actions/github/-/github-6.0.1.tgz",
"integrity": "sha512-alScpSVnYmjNEXboZjarjukQEzgCRmjMv6Xj47fsdnqGS73bjJNDpiiXmp8jr0UZLdUB6d9jW63IcmddUP+l0g==", "integrity": "sha512-xbZVcaqD4XnQAe35qSQqskb3SqIAfRyLBrHMd/8TuL7hJSz2QtbDwnNM8zWx4zO5l2fnGtseNE3MbEvD7BxVMw==",
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"@actions/http-client": "^2.2.0", "@actions/http-client": "^2.2.0",
"@octokit/core": "^5.0.1", "@octokit/core": "^5.0.1",
"@octokit/plugin-paginate-rest": "^9.0.0", "@octokit/plugin-paginate-rest": "^9.2.2",
"@octokit/plugin-rest-endpoint-methods": "^10.0.0" "@octokit/plugin-rest-endpoint-methods": "^10.4.0",
"@octokit/request": "^8.4.1",
"@octokit/request-error": "^5.1.1",
"undici": "^5.28.5"
} }
}, },
"node_modules/@actions/glob": { "node_modules/@actions/glob": {
@@ -1744,9 +1740,9 @@
} }
}, },
"node_modules/@octokit/endpoint": { "node_modules/@octokit/endpoint": {
"version": "9.0.5", "version": "9.0.6",
"resolved": "https://registry.npmjs.org/@octokit/endpoint/-/endpoint-9.0.5.tgz", "resolved": "https://registry.npmjs.org/@octokit/endpoint/-/endpoint-9.0.6.tgz",
"integrity": "sha512-ekqR4/+PCLkEBF6qgj8WqJfvDq65RH85OAgrtnVp1mSxaXF03u2xW/hUdweGS5654IlC0wkNYC18Z50tSYTAFw==", "integrity": "sha512-H1fNTMA57HbkFESSt3Y9+FBICv+0jFceJFPWDePYlR/iMGrwM5ph+Dd4XRQs+8X+PUFURLQgX9ChPfhJ/1uNQw==",
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"@octokit/types": "^13.1.0", "@octokit/types": "^13.1.0",
@@ -1777,9 +1773,9 @@
"license": "MIT" "license": "MIT"
}, },
"node_modules/@octokit/plugin-paginate-rest": { "node_modules/@octokit/plugin-paginate-rest": {
"version": "9.2.1", "version": "9.2.2",
"resolved": "https://registry.npmjs.org/@octokit/plugin-paginate-rest/-/plugin-paginate-rest-9.2.1.tgz", "resolved": "https://registry.npmjs.org/@octokit/plugin-paginate-rest/-/plugin-paginate-rest-9.2.2.tgz",
"integrity": "sha512-wfGhE/TAkXZRLjksFXuDZdmGnJQHvtU/joFQdweXUgzo1XwvBCD4o4+75NtFfjfLK5IwLf9vHTfSiU3sLRYpRw==", "integrity": "sha512-u3KYkGF7GcZnSD/3UP0S7K5XUFT2FkOQdcfXZGZQPGv3lm4F2Xbf71lvjldr8c1H3nNbF+33cLEkWYbokGWqiQ==",
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"@octokit/types": "^12.6.0" "@octokit/types": "^12.6.0"
@@ -1837,13 +1833,13 @@
} }
}, },
"node_modules/@octokit/request": { "node_modules/@octokit/request": {
"version": "8.4.0", "version": "8.4.1",
"resolved": "https://registry.npmjs.org/@octokit/request/-/request-8.4.0.tgz", "resolved": "https://registry.npmjs.org/@octokit/request/-/request-8.4.1.tgz",
"integrity": "sha512-9Bb014e+m2TgBeEJGEbdplMVWwPmL1FPtggHQRkV+WVsMggPtEkLKPlcVYm/o8xKLkpJ7B+6N8WfQMtDLX2Dpw==", "integrity": "sha512-qnB2+SY3hkCmBxZsR/MPCybNmbJe4KAlfWErXq+rBKkQJlbjdJeS85VI9r8UqeLYLvnAenU8Q1okM/0MBsAGXw==",
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"@octokit/endpoint": "^9.0.1", "@octokit/endpoint": "^9.0.6",
"@octokit/request-error": "^5.1.0", "@octokit/request-error": "^5.1.1",
"@octokit/types": "^13.1.0", "@octokit/types": "^13.1.0",
"universal-user-agent": "^6.0.0" "universal-user-agent": "^6.0.0"
}, },
@@ -1852,9 +1848,9 @@
} }
}, },
"node_modules/@octokit/request-error": { "node_modules/@octokit/request-error": {
"version": "5.1.0", "version": "5.1.1",
"resolved": "https://registry.npmjs.org/@octokit/request-error/-/request-error-5.1.0.tgz", "resolved": "https://registry.npmjs.org/@octokit/request-error/-/request-error-5.1.1.tgz",
"integrity": "sha512-GETXfE05J0+7H2STzekpKObFe765O5dlAKUTLNGeH+x47z7JjXHfsHKo5z21D/o/IOZTUEI6nyWyR+bZVP/n5Q==", "integrity": "sha512-v9iyEQJH6ZntoENr9/yXxjuezh4My67CBSu9r6Ve/05Iu5gNgnisNWOsoJHTP6k0Rr0+HQIpnH+kyammu90q/g==",
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"@octokit/types": "^13.1.0", "@octokit/types": "^13.1.0",
@@ -6085,9 +6081,9 @@
} }
}, },
"node_modules/undici": { "node_modules/undici": {
"version": "5.28.4", "version": "5.29.0",
"resolved": "https://registry.npmjs.org/undici/-/undici-5.28.4.tgz", "resolved": "https://registry.npmjs.org/undici/-/undici-5.29.0.tgz",
"integrity": "sha512-72RFADWFqKmUb2hmmvNODKL3p9hcB6Gt2DOQMis1SEBaV6a4MH8soBvzg+95CYhCKPFedut2JY9bMfrDl9D23g==", "integrity": "sha512-raqeBD6NQK4SkWhQzeYKd1KmIG6dllBOTt55Rmkt4HtI9mwdWtJljnrXjAFUBLTSN67HWrOIZ3EPF4kjUw80Bg==",
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"@fastify/busboy": "^2.0.0" "@fastify/busboy": "^2.0.0"
+11 -9
View File
@@ -18,7 +18,7 @@
}, },
"repository": { "repository": {
"type": "git", "type": "git",
"url": "git+https://github.com/actions-rs/audit.git" "url": "github:rustsec/audit-check"
}, },
"keywords": [ "keywords": [
"actions", "actions",
@@ -31,25 +31,27 @@
"author": "actions-rs", "author": "actions-rs",
"license": "MIT", "license": "MIT",
"bugs": { "bugs": {
"url": "https://github.com/actions-rs/audit-check/issues" "url": "https://github.com/rustsec/audit-check/issues"
}, },
"dependencies": { "dependencies": {
"@actions/core": "^1.11.1",
"@actions/github": "^6.0.1",
"@clechasseur/rs-actions-core": "^3.0.5", "@clechasseur/rs-actions-core": "^3.0.5",
"nunjucks": "^3.2.4" "nunjucks": "^3.2.4"
}, },
"devDependencies": { "devDependencies": {
"@typescript-eslint/parser": "^6.21.0", "@types/jest": "^29.5.12",
"@types/node": "^20.11.17",
"@typescript-eslint/eslint-plugin": "^6.21.0", "@typescript-eslint/eslint-plugin": "^6.21.0",
"ts-node": "^10.9.2", "@typescript-eslint/parser": "^6.21.0",
"@vercel/ncc": "0.38.1",
"eslint": "^8.56.0", "eslint": "^8.56.0",
"eslint-config-prettier": "^9.1.0", "eslint-config-prettier": "^9.1.0",
"eslint-plugin-prettier": "^5.1.3", "eslint-plugin-prettier": "^5.1.3",
"@types/jest": "^29.5.12",
"@types/node": "^20.11.17",
"@vercel/ncc": "0.38.1",
"jest": "^29.7.0", "jest": "^29.7.0",
"prettier": "^3.2.5",
"ts-jest": "^29.1.2", "ts-jest": "^29.1.2",
"typescript": "^5.3.3", "ts-node": "^10.9.2",
"prettier": "^3.2.5" "typescript": "^5.3.3"
} }
} }
+6 -1
View File
@@ -8,6 +8,7 @@ import { input } from '@clechasseur/rs-actions-core';
export interface Input { export interface Input {
token: string; token: string;
ignore: string[]; ignore: string[];
new_issue_labels: string[];
workingDirectory: string; workingDirectory: string;
} }
@@ -15,6 +16,10 @@ export function get(): Input {
return { return {
token: input.getInput('token', { required: true }), token: input.getInput('token', { required: true }),
ignore: input.getInputList('ignore', { required: false }), ignore: input.getInputList('ignore', { required: false }),
workingDirectory: input.getInput('working-directory', { required: false }) ?? '.', new_issue_labels: input.getInputList('new-issue-labels', {
required: false,
}),
workingDirectory:
input.getInput('working-directory', { required: false }) ?? '.',
}; };
} }
+12 -3
View File
@@ -1,5 +1,5 @@
import * as process from 'process';
import * as os from 'os'; import * as os from 'os';
import * as process from 'process';
import * as core from '@actions/core'; import * as core from '@actions/core';
import * as github from '@actions/github'; import * as github from '@actions/github';
@@ -54,6 +54,7 @@ function removeTrailingSlash(str) {
} }
export async function run(actionInput: input.Input): Promise<void> { export async function run(actionInput: input.Input): Promise<void> {
const labels = actionInput.new_issue_labels;
const ignore = actionInput.ignore; const ignore = actionInput.ignore;
const workingDirectory = removeTrailingSlash(actionInput.workingDirectory); const workingDirectory = removeTrailingSlash(actionInput.workingDirectory);
const report = await getData(ignore, workingDirectory); const report = await getData(ignore, workingDirectory);
@@ -90,11 +91,19 @@ export async function run(actionInput: input.Input): Promise<void> {
// const octokit = github.getOctokit(actionInput.token, {userAgent: USER_AGENT}); // const octokit = github.getOctokit(actionInput.token, {userAgent: USER_AGENT});
const advisories = report.vulnerabilities.list; const advisories = report.vulnerabilities.list;
if (github.context.eventName == 'schedule') { if (
github.context.eventName == 'schedule' ||
github.context.eventName == 'workflow_dispatch'
) {
core.debug( core.debug(
'Action was triggered on a schedule event, creating an Issues report', 'Action was triggered on a schedule event, creating an Issues report',
); );
await reporter.reportIssues(actionInput.token, advisories, warnings); await reporter.reportIssues(
actionInput.token,
advisories,
warnings,
labels,
);
} else { } else {
core.debug( core.debug(
`Action was triggered on a ${github.context.eventName} event, creating a Check report`, `Action was triggered on a ${github.context.eventName} event, creating a Check report`,
+5 -3
View File
@@ -166,7 +166,7 @@ export async function reportCheck(
vulnerabilities: Array<interfaces.Vulnerability>, vulnerabilities: Array<interfaces.Vulnerability>,
warnings: Array<interfaces.Warning>, warnings: Array<interfaces.Warning>,
): Promise<void> { ): Promise<void> {
const client = github.getOctokit(token, {userAgent: USER_AGENT}); const client = github.getOctokit(token, { userAgent: USER_AGENT });
const reporter = new checks.CheckReporter(client.rest, 'Security audit'); const reporter = new checks.CheckReporter(client.rest, 'Security audit');
const stats = getStats(vulnerabilities, warnings); const stats = getStats(vulnerabilities, warnings);
const summary = getSummary(stats); const summary = getSummary(stats);
@@ -235,7 +235,7 @@ async function alreadyReported(
advisoryId: string, advisoryId: string,
): Promise<boolean> { ): Promise<boolean> {
const { owner, repo } = github.context.repo; const { owner, repo } = github.context.repo;
const client = github.getOctokit(token, {userAgent: USER_AGENT}); const client = github.getOctokit(token, { userAgent: USER_AGENT });
const results = await client.rest.search.issuesAndPullRequests({ const results = await client.rest.search.issuesAndPullRequests({
q: `${advisoryId} in:title repo:${owner}/${repo}`, q: `${advisoryId} in:title repo:${owner}/${repo}`,
per_page: 1, // eslint-disable-line @typescript-eslint/camelcase per_page: 1, // eslint-disable-line @typescript-eslint/camelcase
@@ -256,10 +256,11 @@ export async function reportIssues(
token: string, token: string,
vulnerabilities: Array<interfaces.Vulnerability>, vulnerabilities: Array<interfaces.Vulnerability>,
warnings: Array<interfaces.Warning>, warnings: Array<interfaces.Warning>,
labels: string[],
): Promise<void> { ): Promise<void> {
const { owner, repo } = github.context.repo; const { owner, repo } = github.context.repo;
const client = github.getOctokit(token, {userAgent: USER_AGENT}); const client = github.getOctokit(token, { userAgent: USER_AGENT });
for (const vulnerability of vulnerabilities) { for (const vulnerability of vulnerabilities) {
const reported = await alreadyReported( const reported = await alreadyReported(
@@ -278,6 +279,7 @@ export async function reportIssues(
repo: repo, repo: repo,
title: `${vulnerability.advisory.id}: ${vulnerability.advisory.title}`, title: `${vulnerability.advisory.id}: ${vulnerability.advisory.title}`,
body: body, body: body,
labels,
}); });
core.info( core.info(
`Created an issue for ${vulnerability.advisory.id}: ${issue.data.html_url}`, `Created an issue for ${vulnerability.advisory.id}: ${issue.data.html_url}`,