|
46 | 46 | - uses: Swatinem/rust-cache@v2 |
47 | 47 | - name: Run tests |
48 | 48 | run: cargo test --workspace |
| 49 | + |
| 50 | + audit: |
| 51 | + runs-on: ubuntu-latest |
| 52 | + steps: |
| 53 | + - uses: actions/checkout@v4 |
| 54 | + - uses: dtolnay/rust-toolchain@stable |
| 55 | + - uses: Swatinem/rust-cache@v2 |
| 56 | + - name: Install cargo-audit |
| 57 | + run: cargo install cargo-audit --locked |
| 58 | + # Blocking on any advisory not listed below — a newly introduced |
| 59 | + # vulnerability fails this job. Every `--ignore` is a pre-existing |
| 60 | + # transitive-dependency advisory tolerated today because the fix is a |
| 61 | + # dependency version bump, and version bumps for the published |
| 62 | + # `rustmotion` crate are being handled separately from this workstream |
| 63 | + # (crates/rustmotion/Cargo.toml, orchestrator-owned). Unmaintained/ |
| 64 | + # unsound/yanked advisories (17 as of 2026-09-22) print but do not fail |
| 65 | + # the job — that's `cargo audit`'s own default, left unchanged here. |
| 66 | + # |
| 67 | + # Review by 2026-12-22, or sooner once the dependency bumps land: |
| 68 | + # RUSTSEC-2025-0008 — openh264-sys2 0.6.6, heap overflow in decoding. |
| 69 | + # Direct dependency of the published `rustmotion` crate. Fix: openh264 >=0.8.0. |
| 70 | + # RUSTSEC-2026-0204 — crossbeam-epoch 0.9.18, invalid pointer deref in `fmt::Pointer`. |
| 71 | + # Via rayon-core <- exr <- image, reaches rustmotion-core/-components. Fix: >=0.9.20. |
| 72 | + # RUSTSEC-2026-0195, RUSTSEC-2026-0194 — quick-xml 0.38.4 / 0.39.4, DoS + quadratic runtime. |
| 73 | + # 0.38.4 via syntect reaches the published crates; 0.39.4 via dioxus-desktop/rfd is |
| 74 | + # rustmotion-studio-only (Linux/Wayland file dialogs). Fix: >=0.41.0. |
| 75 | + # RUSTSEC-2026-0285 — rustls 0.23.37, TLS 1.3 handshake level-boundary bug. |
| 76 | + # Via ureq, used by rustmotion/rustmotion-core for Google Fonts + Iconify fetches. Fix: >=0.23.45. |
| 77 | + # RUSTSEC-2026-0104, RUSTSEC-2026-0098, RUSTSEC-2026-0099, RUSTSEC-2026-0049 — rustls-webpki |
| 78 | + # 0.103.9, four CRL/name-constraint parsing bugs. Same ureq path as rustls above. |
| 79 | + # Fix: >=0.103.13,<0.104.0-alpha.1 (or the matching 0.104 alpha per advisory). |
| 80 | + # RUSTSEC-2026-0257 — webbrowser 1.2.1, BROWSER env argument injection on Unix. |
| 81 | + # Via dioxus-desktop, rustmotion-studio only (`publish = false`, never reaches a published |
| 82 | + # crate). Fix: >=1.2.2. |
| 83 | + - name: Audit dependencies |
| 84 | + run: > |
| 85 | + cargo audit |
| 86 | + --ignore RUSTSEC-2025-0008 |
| 87 | + --ignore RUSTSEC-2026-0204 |
| 88 | + --ignore RUSTSEC-2026-0195 |
| 89 | + --ignore RUSTSEC-2026-0194 |
| 90 | + --ignore RUSTSEC-2026-0285 |
| 91 | + --ignore RUSTSEC-2026-0104 |
| 92 | + --ignore RUSTSEC-2026-0098 |
| 93 | + --ignore RUSTSEC-2026-0099 |
| 94 | + --ignore RUSTSEC-2026-0049 |
| 95 | + --ignore RUSTSEC-2026-0257 |
0 commit comments