Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 7 additions & 1 deletion .github/scripts/tests/test_rust_ci_workflows.py
Original file line number Diff line number Diff line change
Expand Up @@ -114,4 +114,10 @@ def test_rust_security_audit_is_narrow_on_prs_and_complete_on_schedule() -> None
assert install["with"]["tool"] == "cargo-audit@0.22.2"
assert "git diff --name-only -z" in run
assert "find . -name Cargo.lock" in run
assert "cargo audit --no-fetch --file" in run
assert "cargo audit --file" in run
# Every iteration fetches: the yanked check resolves crates against the
# index entries fetched by its own invocation, so a no-fetch pass only
# sees whatever the first lockfile happened to warm — each additional
# lockfile in a PR then fails its yanked lookups. (The workflow's comment
# may name the flag; only the invocation form is forbidden.)
assert "cargo audit --no-fetch" not in run
14 changes: 7 additions & 7 deletions .github/workflows/rust-security-audit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -54,15 +54,15 @@ jobs:
fi

status=0
first=1
# No --no-fetch on the later iterations: the yanked check resolves
# crates against the index entries fetched by THIS invocation, so a
# --no-fetch pass only sees whatever the first lockfile happened to
# warm — every additional lockfile in a PR then fails its yanked
# lookups with "No such crate in crates.io index". The repeat
# advisory-db fetch is a fast no-op once the clone is fresh.
for lockfile in "${lockfiles[@]}"; do
echo "::group::cargo audit --file $lockfile"
if (( first )); then
cargo audit --file "$lockfile" || status=1
first=0
else
cargo audit --no-fetch --file "$lockfile" || status=1
fi
cargo audit --file "$lockfile" || status=1
echo "::endgroup::"
done

Expand Down
Loading
Loading