Skip to content

Commit e3a2031

Browse files
beardtheliont
andauthored
ci: pin cargo-audit on the blocking gate, float the weekly canary (#151)
The PR-blocking audit job ran `cargo install --locked cargo-audit` with no version, so the scanner floated to the latest release on every run; a regressed release could red the PR gate repo-wide with no code change. Pin it to 0.22.2, the version the unpinned install currently resolves to and the one the audit-gate learnings were validated against. `cargo install --version X` is an exact pin (not a caret), so this freezes the binary while the advisory DB is still fetched fresh at scan time, which is what the gate actually keys on. Keep a forcing function so the pin cannot silently rot: leave the weekly Scheduled Audit deliberately unpinned as a drift canary. That job is cron-only (never pull_request/push-triggered), so it never gates a merge; floating there surfaces a regressed latest as a red weekly run or a changed report, which is the drift signal, without ever blocking a PR. Also assert the installed version after the pinned install so an accidental future unpin fails loud instead of silently running a different scanner, include the version in the rust-cache key so cache hits stay deterministic, and document the yank/bump path in the step comment. Co-authored-by: t <t@t>
1 parent c296e23 commit e3a2031

2 files changed

Lines changed: 36 additions & 5 deletions

File tree

‎.github/workflows/audit-schedule.yml‎

Lines changed: 12 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,18 @@ jobs:
3737
with:
3838
key: audit-schedule
3939

40-
- name: Install cargo-audit
40+
- name: Install cargo-audit (floating; drift canary)
41+
# Deliberately UNPINNED, unlike the blocking gate in pr-checks.yml. This
42+
# job is cron-only (weekly); it is never pull_request- or push-triggered,
43+
# so it NEVER gates a merge no matter what it does. Floating the scanner
44+
# here is the drift canary: if a newer cargo-audit regresses, at worst
45+
# this weekly run reds (the install step below is unguarded) or its
46+
# visibility report changes, and that is exactly the signal that latest
47+
# has moved and the pinned gate should not be bumped yet. The scan result
48+
# itself never fails the run (the "Full audit report" step is `|| true`
49+
# and the only other hard-fail is a Cargo.lock grep). The point is that
50+
# drift surfaces here without ever blocking a PR. Do NOT pin to match
51+
# pr-checks.yml.
4152
run: cargo install --locked cargo-audit
4253

4354
# Full advisory report with NO suppressions. Run from a scratch dir that

‎.github/workflows/pr-checks.yml‎

Lines changed: 24 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -133,10 +133,30 @@ jobs:
133133
- name: Cache cargo
134134
uses: Swatinem/rust-cache@98c8021b550208e191a6a3145459bfc9fb29c4c0 # v2.8.0
135135
with:
136-
key: audit
137-
138-
- name: Install cargo-audit
139-
run: cargo install --locked cargo-audit
136+
key: audit-0.22.2
137+
138+
- name: Install cargo-audit (pinned)
139+
# Pin the scanner on this BLOCKING gate: an unpinned `cargo install`
140+
# floats to the latest release, so a regressed cargo-audit could red CI
141+
# repo-wide with no code change. Advisory-DB freshness is fetched at scan
142+
# time, independent of the binary, so this does not weaken what the gate
143+
# catches. The weekly Scheduled Audit (audit-schedule.yml) deliberately
144+
# floats to latest as the drift canary; when it shows a newer cargo-audit
145+
# behaving differently, bump this version (and the cache key above) as a
146+
# deliberate maintainer action. If 0.22.2 is ever yanked from crates.io
147+
# this step fails loud until the pin is bumped.
148+
run: |
149+
set -euo pipefail
150+
cargo install --locked --version 0.22.2 cargo-audit
151+
# Assert the pin took effect so an accidental future unpin (or a drift
152+
# off 0.22.2) fails loudly here instead of silently running a different
153+
# scanner. `cargo audit --version` prints "cargo-audit-audit 0.22.2".
154+
installed="$(cargo audit --version)"
155+
echo "cargo-audit installed: $installed"
156+
echo "$installed" | grep -qE '(^| )0\.22\.2($| )' || {
157+
echo "::error::cargo-audit is not the pinned 0.22.2 (got: $installed)"
158+
exit 1
159+
}
140160
141161
# Hard-fail gate. Suppressions live in .cargo/audit.toml (read automatically
142162
# from the repo root), each with no available upstream fix. A green check

0 commit comments

Comments
 (0)