Skip to content

Audit Rust and npm dependencies in CI - #10

Merged
Commanderx-code merged 1 commit into
mainfrom
ci/security-audit
Sep 25, 2026
Merged

Commanderx-code merged 1 commit into
mainfrom
ci/security-audit

Conversation

@Commanderx-code

Copy link
Copy Markdown
Owner

Change

Adds a Security audit workflow (.github/workflows/security-audit.yml) with two jobs:

  • cargo-audit runs cargo audit --file src-tauri/Cargo.lock, using cargo-audit 0.22.2 installed with --locked.
  • npm-audit runs npm audit against package-lock.json.

The workflow runs on pull requests, on pushes to main, every Monday at 06:17 UTC, and on manual dispatch. The weekly run catches advisories that are published against dependencies the repository hasn't changed.

A known vulnerability fails the check. RustSec "unmaintained" and "unsound" notices stay as warnings. There are seven today, all coming from Tauri's GTK stack (glib, proc-macro-error, unic-*), and nothing in this repository can resolve them.

It is a separate workflow so the weekly run doesn't rebuild and install-test every package. The existing Linux packages workflow is unchanged.

docs/development.md now describes the workflow and how to run both audits locally.

Validation

  • Both commands pass locally on the current lockfiles: cargo audit reports 0 vulnerabilities with 7 allowed warnings, and npm audit reports 0 vulnerabilities.
  • The workflow YAML parses. Every run: line is a fixed command with no event-controlled input.
  • This PR runs the new workflow, so its checks show the jobs working in CI.

Review notes

  • The main ruleset does not require the new checks yet. To make a failing audit block merges, add cargo-audit and npm-audit as required status checks.
  • The weekly run can fail with no code change when a new advisory appears. That failure is the point: update the affected dependency, or record a reviewed exception.

🤖 Generated with Claude Code

A new Security audit workflow runs cargo audit against src-tauri/Cargo.lock
and npm audit on pull requests, pushes to main, and weekly, so advisories
published against unchanged dependencies are caught too. Known
vulnerabilities fail the check; RustSec unmaintained/unsound notices (today
seven, all from Tauri's GTK stack) remain warnings.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Commanderx-code
Commanderx-code merged commit f56a71e into main Sep 25, 2026
9 checks passed
@Commanderx-code
Commanderx-code deleted the ci/security-audit branch September 25, 2026 17:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant