2019-10-09 19:32:01 +03:00
2019-10-09 19:29:13 +03:00
2019-10-09 19:29:13 +03:00
2019-10-09 19:29:13 +03:00
2019-10-09 19:29:13 +03:00
2019-10-09 19:29:13 +03:00
2019-10-09 19:29:13 +03:00
2019-10-09 19:29:13 +03:00
2019-10-09 19:29:13 +03:00
2019-10-09 19:29:13 +03:00
2019-10-09 19:29:13 +03:00
2019-10-09 19:29:13 +03:00
2019-10-09 19:32:01 +03:00
2019-10-09 19:29:13 +03:00
2019-10-09 19:29:13 +03:00
2019-10-09 19:29:13 +03:00
2019-10-09 19:29:13 +03:00
2019-10-09 19:29:13 +03:00
2019-10-09 19:29:13 +03:00

Rust audit-check Action

MIT licensed Gitter

Security vulnerabilities audit

This GitHub Action is using cargo-audit to perform an audit for crates with security vulnerabilities.

Usage

Audit changes

We can utilize the GitHub Actions ability to execute workflow only if specific files were changed and execute this Action to check the changed dependencies only:

name: Security audit
on:
  push:
    paths: 
      - '**/Cargo.toml'
      - '**/Cargo.lock'
jobs:
  security_audit:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v1
      - uses: actions-rs/audit-check@v1
        with:
          token: ${{ secrets.GITHUB_TOKEN }}

In that case this Action will create a Check with the advisories found:

Check screenshot

Limitations

Due to token permissions, this Action WILL NOT be able to create Checks for Pull Requests from the forked repositories, see actions-rs/clippy-check#2 for details.
As a fallback this Action will output all advisories found to the stdout.

Scheduled audit

Another option is to use schedule event and execute this Action periodically against the repository default branch HEAD.

name: Security audit
on:
  schedule:
    - cron: '0 0 * * *'
jobs:
  audit:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v1
      - uses: actions-rs/audit-check@alpha
        with:
          token: ${{ secrets.GITHUB_TOKEN }}

With this workflow Action will be executed at midnight on each day and check if there any new advisories appear for crate dependencies.
For each such advisory an issue will be created:

Issue screenshot

Inputs

Name Required Description Type Default
token GitHub token, ${{ secrets.GITHUB_TOKEN }} string
S
Description
No description provided
Readme MIT
4.5 MiB
Languages
TypeScript 98.8%
JavaScript 1.2%