Skip to content

Replace unverified cargo-deny action with checksum-verified install - #390

Draft
sophokles73 with Copilot wants to merge 2 commits into
mainfrom
copilot/fix-code-scanning-alert-74
Draft

sophokles73 with Copilot wants to merge 2 commits into
mainfrom
copilot/fix-code-scanning-alert-74

Conversation

Copilot AI commented Sep 17, 2026 •

Copy link
Copy Markdown

This updates the CI workflow to remove the flagged unverified GitHub Action usage behind alert #74. The cargo deny job now installs a pinned cargo-deny release directly and verifies the archive checksum before execution.

  • Workflow hardening

    • Remove EmbarkStudios/cargo-deny-action from .github/workflows/check.yaml
    • Keep the existing deny job behavior, but execute it via a locally installed pinned binary
  • Verified tool installation

    • Add an explicit CARGO_DENY_VERSION
    • Download the matching release asset for the runner architecture
    • Verify the archive with a pinned SHA-256 before extracting cargo-deny
    • Run cargo deny check --all-features directly
  • Policy cleanup

    • Remove the now-unused poutine allowlist entry from .github/poutine.yml
- name: Install cargo-deny
  run: |
    curl --proto '=https' --tlsv1.2 --silent --show-error --location \
      --output "${archive_path}" \
      "https://github.com/EmbarkStudios/cargo-deny/releases/download/${CARGO_DENY_VERSION}/${asset}"

    echo "${sha256}  ${archive_path}" | sha256sum -c -
    tar -xzf "${archive_path}" -C "${HOME}/.cargo/bin" --strip-components=1 "${asset%.tar.gz}/cargo-deny"

Co-authored-by: sophokles73 <5682135+sophokles73@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix code scanning alert(s) flagged in repository Replace unverified cargo-deny action with checksum-verified install Sep 17, 2026
Copilot AI requested a review from sophokles73 September 17, 2026 11:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants