Skip to content

chore(deps): refresh every dependency the project can move, and close two blind spots #1601

chore(deps): refresh every dependency the project can move, and close two blind spots

chore(deps): refresh every dependency the project can move, and close two blind spots #1601

Workflow file for this run

name: Security
# Dependency-vulnerability scan (cargo-audit) + licence / advisory / source
# policy (cargo-deny) + an extended clippy gate.
#
# Pure-documentation pushes are skipped: they cannot change Cargo.lock or any
# `.rs` code, so there is nothing for these jobs to find. The weekly `schedule`
# cron still re-runs the full suite, so a NEW advisory published against an
# unchanged dependency is caught even when no code is pushed.
on:
push:
branches: [main]
paths-ignore:
- "**/*.md"
- "**/*.txt"
- "screenshots/**"
- "LICENSE*"
- "NOTICE"
- ".gitignore"
- ".codegraph/**"
pull_request:
branches: [main]
paths-ignore:
- "**/*.md"
- "**/*.txt"
- "screenshots/**"
- "LICENSE*"
- "NOTICE"
- ".gitignore"
- ".codegraph/**"
schedule:
- cron: "0 0 * * 1"
workflow_dispatch:
# Cancel superseded PR runs; let every `main` commit finish.
concurrency:
group: security-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
env:
CARGO_TERM_COLOR: always
# Least-privilege default: the audit / deny / clippy-security jobs only read the
# checked-out tree (cargo-audit, cargo-deny, clippy) — none uploads SARIF or
# writes to the repo — so the default GITHUB_TOKEN is narrowed to read-only.
# Resolves the CodeQL `actions/missing-workflow-permissions` alerts (one per job).
permissions:
contents: read
# Every job carries an explicit `timeout-minutes`, for the reason PR #400
# established for `ci.yml` and this file was missed by: without one a job
# inherits GitHub's SIX-HOUR default, and a hung job then blocks a release while
# reporting nothing at all. That is not hypothetical here — `Clippy Security
# Lints` hung for over two hours during the v2.3.7 cut, in a setup step, on a
# job whose observed runtime is 2-3 minutes, and the release waited on it.
#
# Budgets are generous multiples of observed runtime (audit and deny complete in
# under a minute, clippy in 2-3), because the purpose is to bound a hang, not to
# police normal variance on a cold cache.
jobs:
audit:
name: Dependency Audit
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
# Install the PREBUILT binary, never `cargo install` (build-from-source):
# 1. compiling the tool on every run dwarfs downloading it, and
# 2. `rust-toolchain.toml` is a directory override, so a build-from-source
# install is subject to this repo's rustc pin -- if a tool's own MSRV
# ever rises above that pin, the SECURITY gate is what breaks. The
# prebuilt binary only parses `Cargo.lock` and runs under any toolchain.
# Reason 2 was an ACTIVE constraint until the v1.3.0 pin bump (1.86 vs
# cargo-audit's 1.88); it is slack today and can bind again after an MSRV
# change in either direction, so it is kept rather than deleted as history.
- uses: taiki-e/install-action@v2.87.11
with:
tool: cargo-audit
- run: cargo audit
deny:
name: Cargo Deny Check
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
# Prebuilt binary for the same two reasons as the audit job above: it is
# much faster than compiling cargo-deny, and it keeps the security gate
# independent of this repo's rustc pin. Policy lives in `deny.toml`.
- uses: taiki-e/install-action@v2.87.11
with:
tool: cargo-deny
- run: cargo deny check
clippy-security:
name: Clippy Security Lints
runs-on: ubuntu-latest
timeout-minutes: 25
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
- uses: ./.github/actions/rust-setup
with:
components: clippy
cache-key: security-clippy
# The main CI `lint` job already runs `clippy -D warnings` on the DEFAULT
# feature set. This job extends that exact gate to the two non-default,
# security- / FFI-relevant frontend features the default build never
# compiles (and which therefore rot silently):
# * retroachievements - the RA HTTP client + the vendored rcheevos C FFI
# * gpu-timing - the wgpu TIMESTAMP_QUERY readback path
# so a clippy regression in either feature-gated path fails here.
#
# NOTE: the previous `-W clippy::unwrap_used -W clippy::expect_used`
# restriction lints were removed. Under `-D warnings` they promote EVERY
# legitimate `.unwrap()`/`.expect()` (hot paths, tests, build scripts) to
# a hard error, which is what kept this job permanently red. `-D warnings`
# alone is the meaningful, reliable security / quality gate.
- name: Run clippy (-D warnings) incl. RA + GPU-timing features
run: |
cargo clippy --workspace --all-targets \
--features rustynes-frontend/retroachievements,rustynes-frontend/gpu-timing \
-- -D warnings