Repository navigation
chore(deps): refresh every dependency the project can move, and close two blind spots #1601
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Security | |
| # Dependency-vulnerability scan (cargo-audit) + licence / advisory / source | |
| # policy (cargo-deny) + an extended clippy gate. | |
| # | |
| # Pure-documentation pushes are skipped: they cannot change Cargo.lock or any | |
| # `.rs` code, so there is nothing for these jobs to find. The weekly `schedule` | |
| # cron still re-runs the full suite, so a NEW advisory published against an | |
| # unchanged dependency is caught even when no code is pushed. | |
| on: | |
| push: | |
| branches: [main] | |
| paths-ignore: | |
| - "**/*.md" | |
| - "**/*.txt" | |
| - "screenshots/**" | |
| - "LICENSE*" | |
| - "NOTICE" | |
| - ".gitignore" | |
| - ".codegraph/**" | |
| pull_request: | |
| branches: [main] | |
| paths-ignore: | |
| - "**/*.md" | |
| - "**/*.txt" | |
| - "screenshots/**" | |
| - "LICENSE*" | |
| - "NOTICE" | |
| - ".gitignore" | |
| - ".codegraph/**" | |
| schedule: | |
| - cron: "0 0 * * 1" | |
| workflow_dispatch: | |
| # Cancel superseded PR runs; let every `main` commit finish. | |
| concurrency: | |
| group: security-${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| env: | |
| CARGO_TERM_COLOR: always | |
| # Least-privilege default: the audit / deny / clippy-security jobs only read the | |
| # checked-out tree (cargo-audit, cargo-deny, clippy) — none uploads SARIF or | |
| # writes to the repo — so the default GITHUB_TOKEN is narrowed to read-only. | |
| # Resolves the CodeQL `actions/missing-workflow-permissions` alerts (one per job). | |
| permissions: | |
| contents: read | |
| # Every job carries an explicit `timeout-minutes`, for the reason PR #400 | |
| # established for `ci.yml` and this file was missed by: without one a job | |
| # inherits GitHub's SIX-HOUR default, and a hung job then blocks a release while | |
| # reporting nothing at all. That is not hypothetical here — `Clippy Security | |
| # Lints` hung for over two hours during the v2.3.7 cut, in a setup step, on a | |
| # job whose observed runtime is 2-3 minutes, and the release waited on it. | |
| # | |
| # Budgets are generous multiples of observed runtime (audit and deny complete in | |
| # under a minute, clippy in 2-3), because the purpose is to bound a hang, not to | |
| # police normal variance on a cold cache. | |
| jobs: | |
| audit: | |
| name: Dependency Audit | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - uses: actions/checkout@v7 | |
| with: | |
| persist-credentials: false | |
| # Install the PREBUILT binary, never `cargo install` (build-from-source): | |
| # 1. compiling the tool on every run dwarfs downloading it, and | |
| # 2. `rust-toolchain.toml` is a directory override, so a build-from-source | |
| # install is subject to this repo's rustc pin -- if a tool's own MSRV | |
| # ever rises above that pin, the SECURITY gate is what breaks. The | |
| # prebuilt binary only parses `Cargo.lock` and runs under any toolchain. | |
| # Reason 2 was an ACTIVE constraint until the v1.3.0 pin bump (1.86 vs | |
| # cargo-audit's 1.88); it is slack today and can bind again after an MSRV | |
| # change in either direction, so it is kept rather than deleted as history. | |
| - uses: taiki-e/install-action@v2.87.11 | |
| with: | |
| tool: cargo-audit | |
| - run: cargo audit | |
| deny: | |
| name: Cargo Deny Check | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - uses: actions/checkout@v7 | |
| with: | |
| persist-credentials: false | |
| # Prebuilt binary for the same two reasons as the audit job above: it is | |
| # much faster than compiling cargo-deny, and it keeps the security gate | |
| # independent of this repo's rustc pin. Policy lives in `deny.toml`. | |
| - uses: taiki-e/install-action@v2.87.11 | |
| with: | |
| tool: cargo-deny | |
| - run: cargo deny check | |
| clippy-security: | |
| name: Clippy Security Lints | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 25 | |
| steps: | |
| - uses: actions/checkout@v7 | |
| with: | |
| persist-credentials: false | |
| - uses: ./.github/actions/rust-setup | |
| with: | |
| components: clippy | |
| cache-key: security-clippy | |
| # The main CI `lint` job already runs `clippy -D warnings` on the DEFAULT | |
| # feature set. This job extends that exact gate to the two non-default, | |
| # security- / FFI-relevant frontend features the default build never | |
| # compiles (and which therefore rot silently): | |
| # * retroachievements - the RA HTTP client + the vendored rcheevos C FFI | |
| # * gpu-timing - the wgpu TIMESTAMP_QUERY readback path | |
| # so a clippy regression in either feature-gated path fails here. | |
| # | |
| # NOTE: the previous `-W clippy::unwrap_used -W clippy::expect_used` | |
| # restriction lints were removed. Under `-D warnings` they promote EVERY | |
| # legitimate `.unwrap()`/`.expect()` (hot paths, tests, build scripts) to | |
| # a hard error, which is what kept this job permanently red. `-D warnings` | |
| # alone is the meaningful, reliable security / quality gate. | |
| - name: Run clippy (-D warnings) incl. RA + GPU-timing features | |
| run: | | |
| cargo clippy --workspace --all-targets \ | |
| --features rustynes-frontend/retroachievements,rustynes-frontend/gpu-timing \ | |
| -- -D warnings |