Skip to content

chore(ci): added dependabot, cargo-audit, cargo-deny - #16

Merged
gyorgybalazsi merged 2 commits into
mainfrom
chore/ci/security-tooling
Oct 5, 2026
Merged

gyorgybalazsi merged 2 commits into
mainfrom
chore/ci/security-tooling

Conversation

@schronck

Copy link
Copy Markdown
Contributor

Summary

Adds security tooling matching the pattern in dec-party-manager:

  • .github/dependabot.yml — monthly cargo + github-actions updates, grouped minor/patch
  • .github/workflows/security.yml — cargo-audit (rustsec/audit-check) + cargo-deny check advisories on push/PR

Part of the org-wide security tooling rollout (tracking sheet in bitsafe/dlc-link-security-tooling-rollout.md). Cargo.toml has only crates.io deps — no SSH setup needed.

Test plan

  • CI runs on this PR and both jobs pass
  • Dependabot picks up the config (Insights → Dependency graph → Dependabot)

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedrand@​0.8.5 ⏵ 0.8.6100 +1100 +193100100

View full report

@gyorgybalazsi
gyorgybalazsi merged commit 5f410d1 into main Oct 5, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants