diff --git a/.github/workflows/code_style.yml b/.github/workflows/code_style.yml index 620760ae..bd964729 100644 --- a/.github/workflows/code_style.yml +++ b/.github/workflows/code_style.yml @@ -16,6 +16,15 @@ jobs: - name: Check formatting run: cargo fmt --all -- --check + deny-check: + name: cargo-deny + runs-on: ubuntu-latest + steps: + - name: Checkout repository + uses: actions/checkout@v6 + - name: Run cargo deny + uses: EmbarkStudios/cargo-deny-action@v2 + clippy: name: Clippy (${{ matrix.name }}) runs-on: ubuntu-latest @@ -71,18 +80,18 @@ jobs: # Roll-up job for branch protection code-style: - name: Code Style (fmt + clippy) + name: Code Style (fmt + clippy + deny) runs-on: ubuntu-latest if: always() - needs: [format, clippy, clippy-windows] + needs: [format, clippy, clippy-windows, deny-check] steps: - run: | - if [[ "${{ needs.format.result }}" != "success" || "${{ needs.clippy.result }}" != "success" ]]; then + if [[ "${{ needs.format.result }}" != "success" || "${{ needs.clippy.result }}" != "success" || "${{ needs.deny-check.result }}" != "success" ]]; then echo "One or more jobs failed" exit 1 fi - # clippy-windows only runs on main PRs, so skip/success are both acceptable - if [[ "${{ needs.clippy-windows.result }}" == "failure" ]]; then - echo "Windows clippy failed" + # clippy-windows only runs on main PRs, so skipped is acceptable but failure is not + if [[ "${{ needs.clippy-windows.result }}" != "success" && "${{ needs.clippy-windows.result }}" != "skipped" ]]; then + echo "Windows clippy failed: ${{ needs.clippy-windows.result }}" exit 1 fi diff --git a/deny.toml b/deny.toml new file mode 100644 index 00000000..80aa2215 --- /dev/null +++ b/deny.toml @@ -0,0 +1,50 @@ +[advisories] +unmaintained = "workspace" +yanked = "deny" +ignore = [ + # Pre-existing advisories — tracked for upgrade in separate PRs + # serde_yml unsound/unmaintained — direct dep, upgrade tracked separately + "RUSTSEC-2025-0068", + # tokio-tar PAX header parsing — sandbox containers only + "RUSTSEC-2025-0111", + # wasmtime fd_renumber host panic — WASIp1, mitigated by fuel limits + "RUSTSEC-2025-0046", + # wasmtime shared linear memory unsoundness — no shared memory in our guests + "RUSTSEC-2025-0118", + # wasmtime guest-controlled resource exhaustion — mitigated by fuel/memory limits + "RUSTSEC-2026-0020", + # wasmtime wasi:http/types.fields panic — mitigated by fuel limits + "RUSTSEC-2026-0021", +] + +[licenses] +version = 2 +allow = [ + "MIT", + "Apache-2.0", + "Apache-2.0 WITH LLVM-exception", + "BSD-2-Clause", + "BSD-3-Clause", + "ISC", + "Unicode-3.0", + "Unicode-DFS-2016", + "OpenSSL", + "Zlib", + "MPL-2.0", + "0BSD", + "BSL-1.0", + "CC0-1.0", + "Unlicense", + "CDLA-Permissive-2.0", +] +unused-allowed-license = "allow" + +[bans] +multiple-versions = "warn" +wildcards = "deny" + +[sources] +unknown-registry = "deny" +unknown-git = "deny" +allow-registry = ["https://github.com/rust-lang/crates.io-index"] +allow-git = [] diff --git a/scripts/ci/quality_gate_strict.sh b/scripts/ci/quality_gate_strict.sh new file mode 100755 index 00000000..ed595964 --- /dev/null +++ b/scripts/ci/quality_gate_strict.sh @@ -0,0 +1,21 @@ +#!/usr/bin/env bash +set -euo pipefail + +# Ensure we are running from the repository root +cd "$(git rev-parse --show-toplevel)" + +echo "==> fmt check" +cargo fmt --all -- --check + +echo "==> clippy (all warnings)" +cargo clippy --locked --all --benches --tests --examples --all-features -- -D warnings + +echo "==> cargo deny" +if ! command -v cargo-deny &>/dev/null; then + echo "ERROR: cargo-deny not installed (install with: cargo install cargo-deny)" + exit 1 +fi +cargo deny check + +echo "==> tests" +cargo test --locked