Skip to content

chore: implement more supply chain hardening - #11

Merged
prom3theu5 merged 1 commit into
mainfrom
feat/hardening
Sep 2, 2026
Merged

prom3theu5 merged 1 commit into
mainfrom
feat/hardening

Conversation

@prom3theu5

@prom3theu5 prom3theu5 commented Sep 2, 2026 •

Copy link
Copy Markdown
Member

It doesnt look like minimum package age is gonna hit untill rust mainline release around november - if its even finished by then, so we will pin on a known nightly, where it is functional.

Also introduces go vet, and go deny

Summary by CodeRabbit

  • Security

    • Strengthened dependency supply-chain protections by rejecting newly published or untrusted packages and checking licenses, advisories, and sources.
    • Added automated auditing safeguards for third-party Rust dependencies.
  • Quality

    • Added automated pull-request checks for formatting, linting, builds, tests, and dependency validation.
    • Standardized the project’s Rust toolchain and required development components.
  • Documentation

    • Expanded build documentation with toolchain, testing, and dependency-pinning guidance.

It doesnt look like minimum package age is gonna hit untill rust
mainline release around november - if its even finished by then, so we
will pin on a known nightly, where it is functional.

Also introduces go vet, and go deny
@prom3theu5
prom3theu5 merged commit 9fc6eb1 into main Sep 2, 2026
2 of 3 checks passed
@prom3theu5
prom3theu5 deleted the feat/hardening branch September 2, 2026 23:59
@coderabbitai

coderabbitai Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Team

Run ID: 414e491a-6e0c-46c0-8ff8-a1484eae0344

📥 Commits

Reviewing files that changed from the base of the PR and between 4604435 and f4cde86.

⛔ Files ignored due to path filters (1)
  • supply-chain/imports.lock is excluded by !**/*.lock
📒 Files selected for processing (7)
  • .cargo/config.toml
  • .github/workflows/ci.yml
  • README.md
  • deny.toml
  • rust-toolchain.toml
  • supply-chain/audits.toml
  • supply-chain/config.toml

📝 Walkthrough

Walkthrough

The PR adds Rust dependency-age controls, cargo-deny and cargo-vet policies, pinned toolchain components, pull-request CI checks, and README documentation for the build and supply-chain workflow.

Changes

Rust supply-chain hardening

Layer / File(s) Summary
Dependency policy and toolchain setup
.cargo/config.toml, deny.toml, rust-toolchain.toml
Cargo rejects registry releases younger than 14 days. deny.toml defines advisory, license, ban, and source policies. The pinned nightly installs rustfmt and clippy.
Cargo-vet configuration
supply-chain/config.toml, supply-chain/audits.toml
cargo-vet receives its format configuration, an audits table, and safe-to-deploy exemptions for the listed crate versions.
CI validation and build documentation
.github/workflows/ci.yml, README.md
Pull-request CI runs formatting, Clippy, builds, tests, cargo-deny, and locked cargo-vet checks. The README documents these checks and the dependency-age rule.

Estimated code review effort: 3 (Moderate) | ~20 minutes

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/hardening

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant