Skip to content

Fixes for security audit #1295

Fixes for security audit

Fixes for security audit #1295

Workflow file for this run

name: Security audit
on:
push:
paths:
- '**/Cargo.toml'
- '**/Cargo.lock'
pull_request:
paths:
- '**/Cargo.toml'
- '**/Cargo.lock'
schedule:
- cron: '0 0 * * *'
workflow_dispatch:
jobs:
audit:
name: Run cargo audit
env:
CARGO_TERM_COLOR: always
runs-on: ubuntu-latest
permissions:
pull-requests: read
contents: read
issues: write
checks: write
steps:
- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@stable
id: rust-toolchain
- uses: actions/cache@v4
with:
path: |
~/.cargo/bin/
~/.cargo/registry/index/
~/.cargo/registry/cache/
~/.cargo/git/db/
key: ${{ runner.os }}-${{ steps.rust-toolchain.outputs.cachekey }}-audit
- uses: rustsec/[email protected]
with:
token: ${{ secrets.GITHUB_TOKEN }}
# Tracked by [#1527](https://github.com/private-attribution/ipa/issues/1527)
# RUSTSEC-2024-0436: paste crate is unmaintained
# RUSTSEC-2024-0437: crash due to uncontrolled recursion in protobuf crate
# RUSTSEC-2025-0014: humantime crate is unmaintained
ignore: RUSTSEC-2024-0436,RUSTSEC-2024-0437,RUSTSEC-2025-0014