Scheduled Audit #6
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Scheduled Audit | |
| # Self-expiring suppression check (companion to the PR-blocking audit gate in | |
| # pr-checks.yml). Runs weekly. It re-runs cargo audit WITHOUT the .cargo/audit.toml | |
| # ignore list to surface the full advisory set for visibility, and it hard-fails | |
| # if the lockfile has moved off the pinned vulnerable versions while the ignores | |
| # are still present, i.e. the upstream fix landed but the ignore was not dropped. | |
| on: | |
| schedule: | |
| - cron: "0 6 * * 1" # Mondays 06:00 UTC | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| env: | |
| CARGO_TERM_COLOR: always | |
| jobs: | |
| scheduled-audit: | |
| name: scheduled audit (no ignores) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Check out repository | |
| uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 | |
| with: | |
| persist-credentials: false | |
| - name: Set up Rust toolchain | |
| uses: dtolnay/rust-toolchain@b3b07ba8b418998c39fb20f53e8b695cdcc8de1b # stable | |
| with: | |
| toolchain: stable | |
| - name: Cache cargo | |
| uses: Swatinem/rust-cache@98c8021b550208e191a6a3145459bfc9fb29c4c0 # v2.8.0 | |
| with: | |
| key: audit-schedule | |
| - name: Install cargo-audit (floating; drift canary) | |
| # Deliberately UNPINNED, unlike the blocking gate in pr-checks.yml. This | |
| # job is cron-only (weekly); it is never pull_request- or push-triggered, | |
| # so it NEVER gates a merge no matter what it does. Floating the scanner | |
| # here is the drift canary: if a newer cargo-audit regresses, at worst | |
| # this weekly run reds (the install step below is unguarded) or its | |
| # visibility report changes, and that is exactly the signal that latest | |
| # has moved and the pinned gate should not be bumped yet. The scan result | |
| # itself never fails the run (the "Full audit report" step is `|| true` | |
| # and the only other hard-fail is a Cargo.lock grep). The point is that | |
| # drift surfaces here without ever blocking a PR. Do NOT pin to match | |
| # pr-checks.yml. | |
| run: cargo install --locked cargo-audit | |
| # Full advisory report with NO suppressions. Run from a scratch dir that | |
| # has no .cargo/audit.toml so the ignore list does not apply; never fail | |
| # the build on this step, it is visibility only. | |
| - name: Full audit report (ignores not applied) | |
| run: | | |
| mkdir -p "$RUNNER_TEMP/full-audit" | |
| cp Cargo.lock "$RUNNER_TEMP/full-audit/Cargo.lock" | |
| cd "$RUNNER_TEMP/full-audit" | |
| { | |
| echo '### Full cargo audit (no ignores applied)' | |
| echo '```' | |
| cargo audit -f Cargo.lock || true | |
| echo '```' | |
| } >> "$GITHUB_STEP_SUMMARY" | |
| # Drift guard: the hickory ignores are only valid while hickory-proto is | |
| # pinned at 0.25.x. If the lockfile has moved past that, the upstream fix | |
| # is in and the ignores in .cargo/audit.toml must be removed. Fail loudly. | |
| - name: Fail if hickory moved past 0.25.x while ignores remain | |
| run: | | |
| set -euo pipefail | |
| version="$(grep -A1 'name = "hickory-proto"' Cargo.lock | grep '^version' | head -1 | cut -d'"' -f2)" | |
| echo "hickory-proto in Cargo.lock: ${version:-not present}" | |
| ignores_present=false | |
| if grep -q 'RUSTSEC-2026-011' .cargo/audit.toml; then | |
| ignores_present=true | |
| fi | |
| # Drift = the lockfile no longer matches what the ignores assume: | |
| # hickory moved off 0.25.x (fix shipped) OR was removed entirely | |
| # (dead ignore entries left behind). Both must fail. | |
| if [ "$ignores_present" = true ] && { [ -z "${version}" ] || [[ "${version}" != 0.25.* ]]; }; then | |
| echo "::error::hickory-proto is ${version:-absent from Cargo.lock} but the RUSTSEC-2026-0118/0119 ignores are still in .cargo/audit.toml. The upstream fix appears to be available or the dependency is gone; remove the ignores." | |
| exit 1 | |
| fi | |
| echo "No drift: ignore list is consistent with the pinned hickory-proto version." |