From 2928ceb6ef60108b4b0b22a0e57ea468967e646a Mon Sep 17 00:00:00 2001 From: Commanderx-code Date: Fri, 25 Sep 2026 12:55:14 -0400 Subject: [PATCH] Audit Rust and npm dependencies in CI A new Security audit workflow runs cargo audit against src-tauri/Cargo.lock and npm audit on pull requests, pushes to main, and weekly, so advisories published against unchanged dependencies are caught too. Known vulnerabilities fail the check; RustSec unmaintained/unsound notices (today seven, all from Tauri's GTK stack) remain warnings. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/security-audit.yml | 35 ++++++++++++++++++++++++++++ docs/development.md | 2 ++ 2 files changed, 37 insertions(+) create mode 100644 .github/workflows/security-audit.yml diff --git a/.github/workflows/security-audit.yml b/.github/workflows/security-audit.yml new file mode 100644 index 0000000..d4b99e6 --- /dev/null +++ b/.github/workflows/security-audit.yml @@ -0,0 +1,35 @@ +name: Security audit +on: + push: + branches: [main] + pull_request: + # Advisories are published against unchanged dependencies too, so audit main weekly. + schedule: + - cron: "17 6 * * 1" + workflow_dispatch: +permissions: + contents: read +concurrency: + group: security-audit-${{ github.event_name }}-${{ github.ref }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} +jobs: + # Fails on any known vulnerability in the locked dependencies. RustSec "unmaintained" and + # "unsound" notices are reported as warnings only; today's come from Tauri's GTK stack. + cargo-audit: + runs-on: ubuntu-24.04 + timeout-minutes: 15 + steps: + - uses: actions/checkout@v4 + - uses: dtolnay/rust-toolchain@stable + - run: cargo install cargo-audit --version 0.22.2 --locked + - run: cargo audit --file src-tauri/Cargo.lock + + npm-audit: + runs-on: ubuntu-24.04 + timeout-minutes: 10 + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-node@v4 + with: + node-version: "22.23.2" + - run: npm audit diff --git a/docs/development.md b/docs/development.md index 05fd634..c0975d6 100644 --- a/docs/development.md +++ b/docs/development.md @@ -35,6 +35,8 @@ The JavaScript suite covers preference migration, project filters, configuration Rust tests exercise temporary Git remotes, fast-forward and divergence behavior, process cancellation and timeouts, Unicode output, private atomic persistence, setup remapping/redaction/import rollback, read-only project task detection, configuration backups and conflicts, catalog completeness, compatibility rejection, and PTY input, resizing, and cancellation. Restic integration tests use a temporary encrypted repository when Restic is installed. +The **Security audit** workflow runs `cargo audit --file src-tauri/Cargo.lock` and `npm audit` on every pull request, every push to main, and weekly, so new advisories against unchanged dependencies are caught too. Run them locally before changing dependencies (`cargo install cargo-audit --locked` once). A known vulnerability fails the check; RustSec "unmaintained" and "unsound" notices are warnings. + Tests do not push real repositories, run personal backups, activate Home Manager, or execute real Toolbox installers. UI changes should also be checked visually in the browser preview and, for native behavior, in the desktop app. ## Updating Commander Toolbox