Skip to content

ci: enforce dependency integrity - #15

Merged
pppolf merged 1 commit into
mainfrom
agent/add-dependency-integrity-gates
Aug 12, 2026
Merged

pppolf merged 1 commit into
mainfrom
agent/add-dependency-integrity-gates

Conversation

@pppolf

@pppolf pppolf commented Aug 12, 2026

Copy link
Copy Markdown
Member

What

  • fail the Go job when go.mod or go.sum is not tidy
  • scan analyzers/Cargo.lock against the current RustSec advisory database
  • use the official cargo-audit 0.22.2 Linux release and verify its publisher-provided SHA-256 before execution
  • keep CI permissions read-only and avoid Actions that require check/issue write access

Why

CI verified downloaded Go modules and ran Rust tests, but it did not reject a stale Go module graph or scan Rust dependencies for known vulnerabilities. The repository release notes describe both as gates, yet ordinary PRs could bypass them.

Impact

Dependency drift and RustSec findings now fail the existing language jobs. Yanked-crate lookup is intentionally disabled because it requires a mutable crates.io index and is maintenance rather than vulnerability detection; version updates are covered separately by Dependabot.

Checks

  • go mod tidy -diff (no drift)
  • cargo-audit 0.22.2 against 1,216 RustSec advisories / 42 locked crates (0 findings)
  • verified cargo-audit version and official release SHA-256 metadata
  • actionlint -verbose .github/workflows/ci.yml
  • YAML parse
  • git diff --check

@pppolf
pppolf marked this pull request as ready for review August 12, 2026 14:11
@pppolf
pppolf merged commit 2171c15 into main Aug 12, 2026
4 checks passed
@NanaseInori
NanaseInori deleted the agent/add-dependency-integrity-gates branch September 16, 2026 09:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant