Skip to content

Commit f56a71e

Browse files
Merge pull request #10 from Commanderx-code/ci/security-audit
Audit Rust and npm dependencies in CI
2 parents 140364a + 2928ceb commit f56a71e

2 files changed

Lines changed: 37 additions & 0 deletions

File tree

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
name: Security audit
2+
on:
3+
push:
4+
branches: [main]
5+
pull_request:
6+
# Advisories are published against unchanged dependencies too, so audit main weekly.
7+
schedule:
8+
- cron: "17 6 * * 1"
9+
workflow_dispatch:
10+
permissions:
11+
contents: read
12+
concurrency:
13+
group: security-audit-${{ github.event_name }}-${{ github.ref }}
14+
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
15+
jobs:
16+
# Fails on any known vulnerability in the locked dependencies. RustSec "unmaintained" and
17+
# "unsound" notices are reported as warnings only; today's come from Tauri's GTK stack.
18+
cargo-audit:
19+
runs-on: ubuntu-24.04
20+
timeout-minutes: 15
21+
steps:
22+
- uses: actions/checkout@v4
23+
- uses: dtolnay/rust-toolchain@stable
24+
- run: cargo install cargo-audit --version 0.22.2 --locked
25+
- run: cargo audit --file src-tauri/Cargo.lock
26+
27+
npm-audit:
28+
runs-on: ubuntu-24.04
29+
timeout-minutes: 10
30+
steps:
31+
- uses: actions/checkout@v4
32+
- uses: actions/setup-node@v4
33+
with:
34+
node-version: "22.23.2"
35+
- run: npm audit

‎docs/development.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -35,6 +35,8 @@ The JavaScript suite covers preference migration, project filters, configuration
3535

3636
Rust tests exercise temporary Git remotes, fast-forward and divergence behavior, process cancellation and timeouts, Unicode output, private atomic persistence, setup remapping/redaction/import rollback, read-only project task detection, configuration backups and conflicts, catalog completeness, compatibility rejection, and PTY input, resizing, and cancellation. Restic integration tests use a temporary encrypted repository when Restic is installed.
3737

38+
The **Security audit** workflow runs `cargo audit --file src-tauri/Cargo.lock` and `npm audit` on every pull request, every push to main, and weekly, so new advisories against unchanged dependencies are caught too. Run them locally before changing dependencies (`cargo install cargo-audit --locked` once). A known vulnerability fails the check; RustSec "unmaintained" and "unsound" notices are warnings.
39+
3840
Tests do not push real repositories, run personal backups, activate Home Manager, or execute real Toolbox installers. UI changes should also be checked visually in the browser preview and, for native behavior, in the desktop app.
3941

4042
## Updating Commander Toolbox

0 commit comments

Comments
 (0)