diff --git a/.github/workflows/security-audit.yml b/.github/workflows/security-audit.yml new file mode 100644 index 0000000..d4b99e6 --- /dev/null +++ b/.github/workflows/security-audit.yml @@ -0,0 +1,35 @@ +name: Security audit +on: + push: + branches: [main] + pull_request: + # Advisories are published against unchanged dependencies too, so audit main weekly. + schedule: + - cron: "17 6 * * 1" + workflow_dispatch: +permissions: + contents: read +concurrency: + group: security-audit-${{ github.event_name }}-${{ github.ref }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} +jobs: + # Fails on any known vulnerability in the locked dependencies. RustSec "unmaintained" and + # "unsound" notices are reported as warnings only; today's come from Tauri's GTK stack. + cargo-audit: + runs-on: ubuntu-24.04 + timeout-minutes: 15 + steps: + - uses: actions/checkout@v4 + - uses: dtolnay/rust-toolchain@stable + - run: cargo install cargo-audit --version 0.22.2 --locked + - run: cargo audit --file src-tauri/Cargo.lock + + npm-audit: + runs-on: ubuntu-24.04 + timeout-minutes: 10 + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-node@v4 + with: + node-version: "22.23.2" + - run: npm audit diff --git a/docs/development.md b/docs/development.md index 05fd634..c0975d6 100644 --- a/docs/development.md +++ b/docs/development.md @@ -35,6 +35,8 @@ The JavaScript suite covers preference migration, project filters, configuration Rust tests exercise temporary Git remotes, fast-forward and divergence behavior, process cancellation and timeouts, Unicode output, private atomic persistence, setup remapping/redaction/import rollback, read-only project task detection, configuration backups and conflicts, catalog completeness, compatibility rejection, and PTY input, resizing, and cancellation. Restic integration tests use a temporary encrypted repository when Restic is installed. +The **Security audit** workflow runs `cargo audit --file src-tauri/Cargo.lock` and `npm audit` on every pull request, every push to main, and weekly, so new advisories against unchanged dependencies are caught too. Run them locally before changing dependencies (`cargo install cargo-audit --locked` once). A known vulnerability fails the check; RustSec "unmaintained" and "unsound" notices are warnings. + Tests do not push real repositories, run personal backups, activate Home Manager, or execute real Toolbox installers. UI changes should also be checked visually in the browser preview and, for native behavior, in the desktop app. ## Updating Commander Toolbox