Compare commits

...

259 Commits
v1.1.2 ... main

Author SHA1 Message Date
Jonas Bushart
65a3b9631b Add dependabot cooldown
This limits how quickly new dependencies are considered for updates.
2025-12-24 21:25:08 +02:00
Jonas Bushart
44f20854bb Merge pull request #133 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2025-12-22 18:46:13 +01:00
pre-commit-ci[bot]
de901a3959 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.35.0 → 0.36.0](https://github.com/python-jsonschema/check-jsonschema/compare/0.35.0...0.36.0)
2025-12-22 17:19:34 +00:00
Jonas Bushart
9aec10154e Merge pull request #131 from actions-rust-lang/pre-commit-ci-update-config 2025-12-15 19:24:08 +01:00
Jonas Bushart
f9a3578e8c Merge pull request #132 from actions-rust-lang/dependabot/github_actions/actions/cache-5.0.1 2025-12-15 19:23:41 +01:00
dependabot[bot]
0e5244db81 Bump actions/cache from 4.3.0 to 5.0.1
Bumps [actions/cache](https://github.com/actions/cache) from 4.3.0 to 5.0.1.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](0057852bfa...9255dc7a25)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-15 18:03:33 +00:00
pre-commit-ci[bot]
bb29bb53c4 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.19.0 → v1.19.1](https://github.com/pre-commit/mirrors-mypy/compare/v1.19.0...v1.19.1)
2025-12-15 17:26:24 +00:00
Jonas Bushart
c1d86a51cc Merge pull request #130 from actions-rust-lang/pre-commit-ci-update-config 2025-12-08 20:34:05 +01:00
pre-commit-ci[bot]
0495a18b2d [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black-pre-commit-mirror: 25.11.0 → 25.12.0](https://github.com/psf/black-pre-commit-mirror/compare/25.11.0...25.12.0)
2025-12-08 17:26:44 +00:00
Jonas Bushart
4328b3826d Merge pull request #129 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2025-12-01 18:44:04 +01:00
pre-commit-ci[bot]
6d8012fcb1 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.18.2 → v1.19.0](https://github.com/pre-commit/mirrors-mypy/compare/v1.18.2...v1.19.0)
2025-12-01 17:30:58 +00:00
Jonas Bushart
e9f7fe6049 Merge pull request #128 from actions-rust-lang/dependabot/github_actions/actions/checkout-6
Bump actions/checkout from 5 to 6
2025-11-24 19:44:45 +01:00
Jonas Bushart
9ef54f77f4 Merge pull request #127 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2025-11-24 19:43:26 +01:00
dependabot[bot]
70479848c2 Bump actions/checkout from 5 to 6
Bumps [actions/checkout](https://github.com/actions/checkout) from 5 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v5...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-11-24 18:37:49 +00:00
pre-commit-ci[bot]
2d82ccc655 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.21.1 → v3.21.2](https://github.com/asottile/pyupgrade/compare/v3.21.1...v3.21.2)
2025-11-24 17:27:05 +00:00
Jonas Bushart
410bbe6de1 Merge pull request #126 from actions-rust-lang/bump-version 2025-11-22 22:50:33 +01:00
Jonas Bushart
f78860393f Update cargo audit to 0.22.0 2025-11-22 22:48:57 +01:00
Jonas Bushart
80738b141e Merge pull request #125 from actions-rust-lang/pre-commit-ci-update-config 2025-11-17 22:08:55 +01:00
pre-commit-ci[bot]
7ef4b10483 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black-pre-commit-mirror: 25.9.0 → 25.11.0](https://github.com/psf/black-pre-commit-mirror/compare/25.9.0...25.11.0)
- [github.com/asottile/pyupgrade: v3.21.0 → v3.21.1](https://github.com/asottile/pyupgrade/compare/v3.21.0...v3.21.1)
- [github.com/python-jsonschema/check-jsonschema: 0.34.1 → 0.35.0](https://github.com/python-jsonschema/check-jsonschema/compare/0.34.1...0.35.0)
2025-11-17 17:22:24 +00:00
Jonas Bushart
bba9e51bf4 Merge pull request #123 from actions-rust-lang/pre-commit-ci-update-config 2025-10-13 23:32:02 +02:00
pre-commit-ci[bot]
52a1147feb [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/PyCQA/isort: 6.1.0 → 7.0.0](https://github.com/PyCQA/isort/compare/6.1.0...7.0.0)
- [github.com/asottile/pyupgrade: v3.20.0 → v3.21.0](https://github.com/asottile/pyupgrade/compare/v3.20.0...v3.21.0)
- [github.com/python-jsonschema/check-jsonschema: 0.34.0 → 0.34.1](https://github.com/python-jsonschema/check-jsonschema/compare/0.34.0...0.34.1)
2025-10-13 17:23:23 +00:00
Jonas Bushart
66172f7628 Update CHANGELOG for 1.2.5 release 2025-10-10 00:38:25 +02:00
Jonas Bushart
5def536b8b Update dependabot update schedule for github-actions 2025-10-10 00:38:25 +02:00
Jonas Bushart
4a72cba61f Merge pull request #122 from Gronner:pin_action_version
Pin cache action commit to current version
2025-10-09 23:57:10 +02:00
Felix Braeunling
5e2f297135 Pin cache action commit to current version 2025-10-07 23:50:49 +02:00
Jonas Bushart
583ea8772c Merge pull request #120 from actions-rust-lang/pre-commit-ci-update-config 2025-10-06 22:54:13 +02:00
pre-commit-ci[bot]
89ba3f6b33 [pre-commit.ci] pre-commit autoupdate
updates:
- https://github.com/psf/blackhttps://github.com/psf/black-pre-commit-mirror
- [github.com/PyCQA/isort: 6.0.1 → 6.1.0](https://github.com/PyCQA/isort/compare/6.0.1...6.1.0)
2025-10-06 17:34:19 +00:00
Jonas Bushart
70fc4c20e4 Merge pull request #119 from actions-rust-lang/pre-commit-ci-update-config 2025-09-23 20:29:50 +02:00
pre-commit-ci[bot]
4d8b4ff0bb [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 25.1.0 → 25.9.0](https://github.com/psf/black/compare/25.1.0...25.9.0)
- [github.com/pre-commit/mirrors-mypy: v1.18.1 → v1.18.2](https://github.com/pre-commit/mirrors-mypy/compare/v1.18.1...v1.18.2)
- [github.com/python-jsonschema/check-jsonschema: 0.33.3 → 0.34.0](https://github.com/python-jsonschema/check-jsonschema/compare/0.33.3...0.34.0)
2025-09-22 17:24:48 +00:00
Jonas Bushart
eb3b7859b5 Merge pull request #118 from actions-rust-lang/pre-commit-ci-update-config 2025-09-15 22:11:58 +02:00
pre-commit-ci[bot]
05dd34f349 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.17.1 → v1.18.1](https://github.com/pre-commit/mirrors-mypy/compare/v1.17.1...v1.18.1)
2025-09-15 17:20:36 +00:00
Jonas Bushart
8ebd4e1425 Merge pull request #117 from actions-rust-lang/dependabot/github_actions/actions/checkout-5
Bump actions/checkout from 4 to 5
2025-09-02 19:56:48 +02:00
dependabot[bot]
e6d416f90f Bump actions/checkout from 4 to 5
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 5.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4...v5)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-09-02 09:59:18 +00:00
Jonas Bushart
a4dbd65a3d Merge pull request #116 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2025-08-18 21:06:02 +02:00
pre-commit-ci[bot]
87ff3c3826 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.33.2 → 0.33.3](https://github.com/python-jsonschema/check-jsonschema/compare/0.33.2...0.33.3)
2025-08-18 17:19:01 +00:00
Jonas Bushart
3f3561f41e Merge pull request #115 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2025-08-11 23:29:29 +02:00
pre-commit-ci[bot]
5edc0086b3 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/pre-commit-hooks: v5.0.0 → v6.0.0](https://github.com/pre-commit/pre-commit-hooks/compare/v5.0.0...v6.0.0)
2025-08-11 17:27:06 +00:00
Jonas Bushart
3cb13c1e64 Merge pull request #114 from actions-rust-lang/pre-commit-ci-update-config 2025-08-04 19:32:03 +02:00
pre-commit-ci[bot]
48add50e98 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.17.0 → v1.17.1](https://github.com/pre-commit/mirrors-mypy/compare/v1.17.0...v1.17.1)
2025-08-04 17:24:37 +00:00
Jonas Bushart
ea01fba7e9 Merge pull request #113 from actions-rust-lang/pre-commit-ci-update-config 2025-07-21 20:23:12 +02:00
pre-commit-ci[bot]
c5575e01da [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.16.1 → v1.17.0](https://github.com/pre-commit/mirrors-mypy/compare/v1.16.1...v1.17.0)
2025-07-21 17:16:06 +00:00
Jonas Bushart
cd3ca6eae4 Merge pull request #112 from actions-rust-lang/pre-commit-ci-update-config 2025-07-07 22:42:49 +02:00
pre-commit-ci[bot]
b7d67def40 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.33.1 → 0.33.2](https://github.com/python-jsonschema/check-jsonschema/compare/0.33.1...0.33.2)
2025-07-07 17:20:22 +00:00
Jonas Bushart
a7064a1ba2 Merge pull request #111 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2025-06-23 20:00:47 +02:00
pre-commit-ci[bot]
a7db12dcc5 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.16.0 → v1.16.1](https://github.com/pre-commit/mirrors-mypy/compare/v1.16.0...v1.16.1)
- [github.com/python-jsonschema/check-jsonschema: 0.33.0 → 0.33.1](https://github.com/python-jsonschema/check-jsonschema/compare/0.33.0...0.33.1)
2025-06-23 17:14:54 +00:00
Jonas Bushart
11b13924b8 Merge pull request #110 from actions-rust-lang/pre-commit-ci-update-config 2025-06-03 00:27:20 +02:00
pre-commit-ci[bot]
9f1309150a [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.15.0 → v1.16.0](https://github.com/pre-commit/mirrors-mypy/compare/v1.15.0...v1.16.0)
2025-06-02 17:12:16 +00:00
Jonas Bushart
fe25052dce Merge pull request #109 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2025-05-27 12:26:54 +02:00
pre-commit-ci[bot]
6c7dd9440d [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.19.1 → v3.20.0](https://github.com/asottile/pyupgrade/compare/v3.19.1...v3.20.0)
2025-05-26 17:11:32 +00:00
Jonas Bushart
06d438a844 Merge pull request #108 from actions-rust-lang/pre-commit-ci-update-config 2025-04-14 19:13:30 +02:00
pre-commit-ci[bot]
8ddd39f6af [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.32.1 → 0.33.0](https://github.com/python-jsonschema/check-jsonschema/compare/0.32.1...0.33.0)
2025-04-14 17:09:22 +00:00
Jonas Bushart
2788809722 Merge pull request #107 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2025-03-31 22:48:47 +02:00
pre-commit-ci[bot]
cdbcf7e247 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.31.3 → 0.32.1](https://github.com/python-jsonschema/check-jsonschema/compare/0.31.3...0.32.1)
2025-03-31 17:09:58 +00:00
Jonas Bushart
c277a4e821 Merge pull request #106 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2025-03-10 22:43:23 +01:00
pre-commit-ci[bot]
29d2c262c8 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.31.2 → 0.31.3](https://github.com/python-jsonschema/check-jsonschema/compare/0.31.2...0.31.3)
2025-03-10 17:13:43 +00:00
Jonas Bushart
1cc5247f68 Fix typo in the README 2025-03-03 21:37:08 +01:00
Jonas Bushart
579aeab71c Update cargo audit to 0.21.2 2025-03-03 21:34:36 +01:00
Jonas Bushart
0a7806b229 Merge pull request #105 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2025-03-03 18:33:26 +01:00
pre-commit-ci[bot]
4fb4af0611 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/PyCQA/isort: 6.0.0 → 6.0.1](https://github.com/PyCQA/isort/compare/6.0.0...6.0.1)
2025-03-03 17:19:00 +00:00
Jonas Bushart
1aae8517bc Merge pull request #104 from actions-rust-lang/pre-commit-ci-update-config 2025-02-24 19:21:08 +01:00
pre-commit-ci[bot]
202eeee8b4 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.31.1 → 0.31.2](https://github.com/python-jsonschema/check-jsonschema/compare/0.31.1...0.31.2)
2025-02-24 17:11:08 +00:00
Jonas Bushart
34bae80559 Merge pull request #103 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2025-02-10 21:47:41 +01:00
pre-commit-ci[bot]
23dacfdca9 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.14.1 → v1.15.0](https://github.com/pre-commit/mirrors-mypy/compare/v1.14.1...v1.15.0)
2025-02-10 17:31:28 +00:00
Jonas Bushart
dafa32a4e4 Merge pull request #102 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2025-02-03 19:22:02 +01:00
pre-commit-ci[bot]
06105d122a [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 24.10.0 → 25.1.0](https://github.com/psf/black/compare/24.10.0...25.1.0)
- [github.com/PyCQA/isort: 5.13.2 → 6.0.0](https://github.com/PyCQA/isort/compare/5.13.2...6.0.0)
- [github.com/python-jsonschema/check-jsonschema: 0.31.0 → 0.31.1](https://github.com/python-jsonschema/check-jsonschema/compare/0.31.0...0.31.1)
2025-02-03 17:40:45 +00:00
Jonas Bushart
af2ca4abcf Merge pull request #101 from actions-rust-lang/pre-commit-ci-update-config 2025-01-15 18:19:25 +01:00
pre-commit-ci[bot]
de806b6f80 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.30.0 → 0.31.0](https://github.com/python-jsonschema/check-jsonschema/compare/0.30.0...0.31.0)
2025-01-13 17:30:39 +00:00
Jonas Bushart
e12665dbfb Merge pull request #100 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2025-01-06 19:18:09 +01:00
pre-commit-ci[bot]
fdc8c6b8ea [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.14.0 → v1.14.1](https://github.com/pre-commit/mirrors-mypy/compare/v1.14.0...v1.14.1)
2025-01-06 17:40:28 +00:00
Jonas Bushart
42ea4d34ab Merge pull request #99 from actions-rust-lang/pre-commit-ci-update-config 2024-12-23 18:55:47 +01:00
pre-commit-ci[bot]
b4380b6dac [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.19.0 → v3.19.1](https://github.com/asottile/pyupgrade/compare/v3.19.0...v3.19.1)
- [github.com/pre-commit/mirrors-mypy: v1.13.0 → v1.14.0](https://github.com/pre-commit/mirrors-mypy/compare/v1.13.0...v1.14.0)
2024-12-23 17:35:08 +00:00
Jonas Bushart
96e0e19d75 Add Changelog entry for new version 2024-12-17 23:41:46 +01:00
Jonas Bushart
d57b2706e6 Some cleanups and typo fixes 2024-12-17 23:41:37 +01:00
Jonas Bushart
6028f82778 Show a better error message when running "cargo audit" fails
Instead of showing a JSONDecodeError print the exit code, stdout, and
stderr visible in the output.

Closes #98
2024-12-17 23:31:44 +01:00
Jonas Bushart
5bcf9487c7 Merge pull request #97 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2024-12-02 20:07:21 +01:00
pre-commit-ci[bot]
165f86c1a6 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.29.4 → 0.30.0](https://github.com/python-jsonschema/check-jsonschema/compare/0.29.4...0.30.0)
2024-12-02 17:39:23 +00:00
Jonas Bushart
5c5da92c03 Update cargo-audit to 0.21.0 2024-11-06 22:21:55 +01:00
Jonas Bushart
17d62dc82d Merge pull request #96 from actions-rust-lang/pre-commit-ci-update-config 2024-10-29 00:02:23 +01:00
pre-commit-ci[bot]
733aff2088 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.18.0 → v3.19.0](https://github.com/asottile/pyupgrade/compare/v3.18.0...v3.19.0)
- [github.com/pre-commit/mirrors-mypy: v1.12.1 → v1.13.0](https://github.com/pre-commit/mirrors-mypy/compare/v1.12.1...v1.13.0)
2024-10-28 17:41:22 +00:00
Jonas Bushart
95e05e5d8e Merge pull request #95 from actions-rust-lang/pre-commit-ci-update-config 2024-10-21 22:30:53 +02:00
pre-commit-ci[bot]
969643f199 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.11.2 → v1.12.1](https://github.com/pre-commit/mirrors-mypy/compare/v1.11.2...v1.12.1)
2024-10-21 17:36:32 +00:00
Jonas Bushart
7614934373 Merge pull request #94 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2024-10-15 08:17:37 +02:00
pre-commit-ci[bot]
946808f018 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 24.8.0 → 24.10.0](https://github.com/psf/black/compare/24.8.0...24.10.0)
- [github.com/asottile/pyupgrade: v3.17.0 → v3.18.0](https://github.com/asottile/pyupgrade/compare/v3.17.0...v3.18.0)
- [github.com/python-jsonschema/check-jsonschema: 0.29.3 → 0.29.4](https://github.com/python-jsonschema/check-jsonschema/compare/0.29.3...0.29.4)
2024-10-14 17:40:00 +00:00
Jonas Bushart
1fcfd212ac List dependencies in readme 2024-10-11 19:46:47 +02:00
Jonas Bushart
d26dd44917 Merge pull request #92 from actions-rust-lang/pre-commit-ci-update-config 2024-10-07 20:25:07 +02:00
pre-commit-ci[bot]
645e2942e8 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/pre-commit-hooks: v4.6.0 → v5.0.0](https://github.com/pre-commit/pre-commit-hooks/compare/v4.6.0...v5.0.0)
2024-10-07 18:01:30 +00:00
Jonas Bushart
965b6233a3 Merge pull request #91 from actions-rust-lang/pre-commit-ci-update-config 2024-09-30 19:42:14 +02:00
pre-commit-ci[bot]
9fe902be91 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.11.1 → v1.11.2](https://github.com/pre-commit/mirrors-mypy/compare/v1.11.1...v1.11.2)
- [github.com/python-jsonschema/check-jsonschema: 0.29.1 → 0.29.3](https://github.com/python-jsonschema/check-jsonschema/compare/0.29.1...0.29.3)
2024-09-30 17:34:43 +00:00
Jonas Bushart
94cd57b0d8 Merge pull request #90 from actions-rust-lang/pre-commit-ci-update-config 2024-08-05 20:15:11 +02:00
pre-commit-ci[bot]
5330a4041e [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 24.4.2 → 24.8.0](https://github.com/psf/black/compare/24.4.2...24.8.0)
- [github.com/pre-commit/mirrors-mypy: v1.11.0 → v1.11.1](https://github.com/pre-commit/mirrors-mypy/compare/v1.11.0...v1.11.1)
2024-08-05 17:41:54 +00:00
Jonas Bushart
531fba54da Merge pull request #89 from actions-rust-lang/remove-locked 2024-07-31 23:47:42 +02:00
Jonas Bushart
31383575a9 Update changelog 2024-07-31 23:42:54 +02:00
Jonas Bushart
e2ad894c8f Install cargo-audit without locked 2024-07-31 23:36:29 +02:00
Jonas Bushart
e4b4ec6817 Add missing changelog entry for 1.2.0 2024-07-31 23:27:02 +02:00
Jonas Bushart
b0169fdb1a Merge pull request #87 from actions-rust-lang/pre-commit-ci-update-config 2024-07-29 23:33:19 +02:00
pre-commit-ci[bot]
de48309832 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.16.0 → v3.17.0](https://github.com/asottile/pyupgrade/compare/v3.16.0...v3.17.0)
- [github.com/python-jsonschema/check-jsonschema: 0.29.0 → 0.29.1](https://github.com/python-jsonschema/check-jsonschema/compare/0.29.0...0.29.1)
2024-07-29 17:35:09 +00:00
Jonas Bushart
f007442857 Merge pull request #86 from actions-rust-lang/pre-commit-ci-update-config 2024-07-22 20:45:50 +02:00
pre-commit-ci[bot]
8a4f84d32b [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.10.1 → v1.11.0](https://github.com/pre-commit/mirrors-mypy/compare/v1.10.1...v1.11.0)
2024-07-22 17:31:48 +00:00
Jonas Bushart
4a6925b10a Merge pull request #85 from actions-rust-lang/pre-commit-ci-update-config 2024-07-15 22:40:17 +02:00
pre-commit-ci[bot]
fae1c3e0b7 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.28.6 → 0.29.0](https://github.com/python-jsonschema/check-jsonschema/compare/0.28.6...0.29.0)
2024-07-15 17:31:05 +00:00
Jonas Bushart
7fe0328ae6 Merge pull request #84 from actions-rust-lang/pre-commit-ci-update-config 2024-07-01 20:10:18 +02:00
pre-commit-ci[bot]
e3466a0192 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.10.0 → v1.10.1](https://github.com/pre-commit/mirrors-mypy/compare/v1.10.0...v1.10.1)
2024-07-01 17:36:58 +00:00
Jonas Bushart
1bedf5d769 Merge pull request #83 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2024-06-24 20:56:11 +02:00
pre-commit-ci[bot]
4ef6a36667 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.28.5 → 0.28.6](https://github.com/python-jsonschema/check-jsonschema/compare/0.28.5...0.28.6)
2024-06-24 17:29:25 +00:00
Jonas Bushart
9a5a196eb1 Merge pull request #82 from actions-rust-lang/pre-commit-ci-update-config 2024-06-17 22:34:24 +02:00
pre-commit-ci[bot]
74871ea769 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.28.4 → 0.28.5](https://github.com/python-jsonschema/check-jsonschema/compare/0.28.4...0.28.5)
2024-06-17 17:29:22 +00:00
Jonas Bushart
62b30a4d5b Merge pull request #81 from actions-rust-lang/pre-commit-ci-update-config 2024-06-10 20:48:49 +02:00
pre-commit-ci[bot]
fa1f058f19 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.15.2 → v3.16.0](https://github.com/asottile/pyupgrade/compare/v3.15.2...v3.16.0)
2024-06-10 17:31:16 +00:00
Jonas Bushart
1e389b4122 Merge pull request #80 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2024-05-29 12:57:32 +02:00
pre-commit-ci[bot]
a6eeed1940 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.28.3 → 0.28.4](https://github.com/python-jsonschema/check-jsonschema/compare/0.28.3...0.28.4)
2024-05-27 17:26:15 +00:00
Jonas Bushart
1ca8cd30ac Merge pull request #79 from actions-rust-lang/pre-commit-ci-update-config 2024-05-13 19:39:29 +02:00
pre-commit-ci[bot]
0ddaadad09 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.28.2 → 0.28.3](https://github.com/python-jsonschema/check-jsonschema/compare/0.28.2...0.28.3)
2024-05-13 17:24:26 +00:00
Jonas Bushart
160ac8b6ed Merge pull request #78 from actions-rust-lang/working-directory 2024-05-05 16:26:46 +03:00
Jonas Bushart
b8800a8c21 Add working directory input to configure where cargo audit executes 2024-05-05 15:46:02 +03:00
Jonas Bushart
1010e1e336 Fix spelling 2024-04-30 22:33:03 +02:00
Jonas Bushart
72f0fdca3b Merge pull request #77 from actions-rust-lang/pre-commit-ci-update-config 2024-04-29 22:43:23 +02:00
pre-commit-ci[bot]
cbff13557b [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 24.4.0 → 24.4.2](https://github.com/psf/black/compare/24.4.0...24.4.2)
- [github.com/pre-commit/mirrors-mypy: v1.9.0 → v1.10.0](https://github.com/pre-commit/mirrors-mypy/compare/v1.9.0...v1.10.0)
2024-04-29 17:35:05 +00:00
Jonas Bushart
08bf11f3ea Merge pull request #76 from actions-rust-lang/pre-commit-ci-update-config 2024-04-15 21:55:21 +02:00
pre-commit-ci[bot]
7049db077c [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 24.3.0 → 24.4.0](https://github.com/psf/black/compare/24.3.0...24.4.0)
- [github.com/python-jsonschema/check-jsonschema: 0.28.1 → 0.28.2](https://github.com/python-jsonschema/check-jsonschema/compare/0.28.1...0.28.2)
2024-04-15 17:32:39 +00:00
Jonas Bushart
e8ea165957 Merge pull request #75 from actions-rust-lang/pre-commit-ci-update-config 2024-04-08 23:01:48 +02:00
pre-commit-ci[bot]
1926841165 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/pre-commit-hooks: v4.5.0 → v4.6.0](https://github.com/pre-commit/pre-commit-hooks/compare/v4.5.0...v4.6.0)
2024-04-08 17:36:39 +00:00
Jonas Bushart
08a60eccbb Merge pull request #74 from actions-rust-lang/pre-commit-ci-update-config 2024-04-01 21:45:01 +02:00
pre-commit-ci[bot]
16af786dc7 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.28.0 → 0.28.1](https://github.com/python-jsonschema/check-jsonschema/compare/0.28.0...0.28.1)
2024-04-01 17:27:21 +00:00
Jonas Bushart
ddc21578b3 Merge pull request #72 from lwshang/cargo_install_locked 2024-03-26 10:38:08 +01:00
Jonas Bushart
c37ceabcab Merge pull request #73 from actions-rust-lang/pre-commit-ci-update-config 2024-03-26 10:36:47 +01:00
pre-commit-ci[bot]
342fdff255 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.15.1 → v3.15.2](https://github.com/asottile/pyupgrade/compare/v3.15.1...v3.15.2)
2024-03-25 17:28:08 +00:00
Linwei Shang
b719ea468c feat: add --locked to cargo install cargo-audit 2024-03-22 17:34:49 -04:00
Jonas Bushart
25528f1e0b Merge pull request #70 from actions-rust-lang/pre-commit-ci-update-config 2024-03-18 18:43:54 +01:00
pre-commit-ci[bot]
f4430692fd [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 24.2.0 → 24.3.0](https://github.com/psf/black/compare/24.2.0...24.3.0)
2024-03-18 17:31:08 +00:00
Jonas Bushart
0f2a92891d Merge pull request #69 from actions-rust-lang/pre-commit-ci-update-config 2024-03-12 22:28:59 +01:00
pre-commit-ci[bot]
c248204ea6 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.8.0 → v1.9.0](https://github.com/pre-commit/mirrors-mypy/compare/v1.8.0...v1.9.0)
2024-03-12 20:13:13 +00:00
Jonas Bushart
e7db852e4a Merge pull request #68 from actions-rust-lang/pre-commit-ci-update-config 2024-02-26 15:32:45 +01:00
pre-commit-ci[bot]
494d723603 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 24.1.1 → 24.2.0](https://github.com/psf/black/compare/24.1.1...24.2.0)
- [github.com/asottile/pyupgrade: v3.15.0 → v3.15.1](https://github.com/asottile/pyupgrade/compare/v3.15.0...v3.15.1)
2024-02-19 17:33:03 +00:00
Jonas Bushart
50559e3f2c Update cargo-audit to 0.20.0 2024-02-18 16:20:11 +01:00
Jonas Bushart
27b62ea8ec Merge pull request #67 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2024-02-12 19:01:22 +01:00
pre-commit-ci[bot]
e207bcd5c9 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.27.4 → 0.28.0](https://github.com/python-jsonschema/check-jsonschema/compare/0.27.4...0.28.0)
2024-02-12 17:24:18 +00:00
Jonas Bushart
7d76eb83b1 Merge pull request #66 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2024-02-05 19:05:28 +01:00
pre-commit-ci[bot]
3e63858e0b [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.27.3 → 0.27.4](https://github.com/python-jsonschema/check-jsonschema/compare/0.27.3...0.27.4)
2024-02-05 17:22:30 +00:00
Jonas Bushart
5308f89d29 Update cargo-audit to 0.19.0 2024-02-03 22:23:31 +01:00
Jonas Bushart
65c5146921 Merge pull request #63 from lwshang/patch-1 2024-02-03 22:19:25 +01:00
Jonas Bushart
6e072ef47a Merge pull request #64 from actions-rust-lang/pre-commit-ci-update-config 2024-01-29 18:30:09 +01:00
pre-commit-ci[bot]
8001bc456e [pre-commit.ci] auto fixes from pre-commit.com hooks
for more information, see https://pre-commit.ci
2024-01-29 17:26:11 +00:00
pre-commit-ci[bot]
cbfe81d58f [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 23.12.1 → 24.1.1](https://github.com/psf/black/compare/23.12.1...24.1.1)
2024-01-29 17:26:02 +00:00
Linwei Shang
89b10d9af6 Upgrade actions/cache to v4
GitHub is deprecating node16 (cache@v3 using).
2024-01-26 14:40:23 -05:00
Jonas Bushart
61ccdfe0c5 Merge pull request #62 from actions-rust-lang/more-debug-logging 2024-01-20 00:28:36 +01:00
Jonas Bushart
959eb6cc5c Update changelog 2024-01-20 00:23:38 +01:00
Jonas Bushart
96eb2dcbe4 Generate lockfile when not existing
Whenever the `file` argument is set give, then cargo audit will not generate the file if it doesn't exist
2024-01-19 23:59:25 +01:00
Jonas Bushart
6943412b48 Add some debug logging for cargo audit 2024-01-19 23:28:36 +01:00
Jonas Bushart
9c29543ade Prepare release 1.1.11 2024-01-18 21:24:19 +01:00
Jonas Bushart
dd7ccfd1ab Merge pull request #56 from mbergkvist/update-permission-example 2024-01-18 21:19:51 +01:00
Jonas Bushart
70c2c66eb8 Merge pull request #61 from actions-rust-lang/pre-commit-ci-update-config 2023-12-25 23:06:34 +01:00
pre-commit-ci[bot]
dfa1ce2e0a [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 23.12.0 → 23.12.1](https://github.com/psf/black/compare/23.12.0...23.12.1)
- [github.com/pre-commit/mirrors-mypy: v1.7.1 → v1.8.0](https://github.com/pre-commit/mirrors-mypy/compare/v1.7.1...v1.8.0)
2023-12-25 17:27:46 +00:00
Jonas Bushart
0c92230a3a Merge pull request #60 from actions-rust-lang/pre-commit-ci-update-config 2023-12-20 00:50:37 +01:00
pre-commit-ci[bot]
170a3db2a9 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 23.11.0 → 23.12.0](https://github.com/psf/black/compare/23.11.0...23.12.0)
- [github.com/PyCQA/isort: 5.13.0 → 5.13.2](https://github.com/PyCQA/isort/compare/5.13.0...5.13.2)
2023-12-18 17:29:43 +00:00
Jonas Bushart
656c0afdef Merge pull request #55 from mbergkvist/add-file-input 2023-12-15 22:15:33 +01:00
Jonas Bushart
ff8437a517 Merge pull request #59 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2023-12-11 18:50:23 +01:00
pre-commit-ci[bot]
8d10929ca1 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/PyCQA/isort: 5.12.0 → 5.13.0](https://github.com/PyCQA/isort/compare/5.12.0...5.13.0)
- [github.com/python-jsonschema/check-jsonschema: 0.27.2 → 0.27.3](https://github.com/python-jsonschema/check-jsonschema/compare/0.27.2...0.27.3)
2023-12-11 17:27:10 +00:00
Jonas Bushart
e46b8c0d76 Merge pull request #58 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2023-11-27 20:40:36 +01:00
pre-commit-ci[bot]
7b3777bcef [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.7.0 → v1.7.1](https://github.com/pre-commit/mirrors-mypy/compare/v1.7.0...v1.7.1)
- [github.com/python-jsonschema/check-jsonschema: 0.27.1 → 0.27.2](https://github.com/python-jsonschema/check-jsonschema/compare/0.27.1...0.27.2)
2023-11-27 17:21:20 +00:00
Jonas Bushart
2ed876b7ce Merge pull request #57 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2023-11-21 20:52:28 +01:00
pre-commit-ci[bot]
69f891a4a1 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 23.10.1 → 23.11.0](https://github.com/psf/black/compare/23.10.1...23.11.0)
- [github.com/pre-commit/mirrors-mypy: v1.6.1 → v1.7.0](https://github.com/pre-commit/mirrors-mypy/compare/v1.6.1...v1.7.0)
2023-11-13 17:29:11 +00:00
Markus Bergkvist
d5ad8c50af Update README example
The write permission on issues in the job sets all other scopes to 'none',
including the global 'read-all', so the action failed on code check-out.
Instead, set the permission for the job, also reduce it to content since
that is all what is required.
2023-11-11 13:38:56 +01:00
Markus Bergkvist
681351af46 Add optional input for Cargo lockfile 2023-11-11 13:02:39 +01:00
Jonas Bushart
d974e8cc12 Merge pull request #54 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2023-11-07 09:31:49 +01:00
pre-commit-ci[bot]
211345ef5d [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.27.0 → 0.27.1](https://github.com/python-jsonschema/check-jsonschema/compare/0.27.0...0.27.1)
2023-11-06 17:21:16 +00:00
Jonas Bushart
001355d0d6 Update CHANGELOG.md 2023-11-02 08:28:22 +01:00
Jonas Bushart
f3073563ad Merge pull request #52 from autarch/patch-1
Use actions/cache@v3, not v4
2023-11-02 08:26:59 +01:00
Dave Rolsky
fe37c9c299 Use actions/cache@v3, not v4
I'm not sure how the PR that changed this passed, but AFAICT there's no v4 of `actions/cache`. The latest major version is `v3`.
2023-11-01 20:06:01 -05:00
Jonas Bushart
d691f93a68 Update cargo-audit to 0.18.3 2023-11-01 21:31:26 +01:00
Jonas Bushart
be90b61479 Merge pull request #50 from reedloden/patch-1 2023-11-01 21:27:34 +01:00
Jonas Bushart
b4cfb1363f Merge pull request #51 from actions-rust-lang/pre-commit-ci-update-config 2023-11-01 21:27:15 +01:00
pre-commit-ci[bot]
6628342aa6 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 23.10.0 → 23.10.1](https://github.com/psf/black/compare/23.10.0...23.10.1)
2023-10-30 17:23:29 +00:00
Reed Loden
c6ef88d85a Bump to actions/cache@v4
Node16.x is deprecated, so bump to newer version.
2023-10-24 12:33:37 -07:00
Jonas Bushart
a69554ff2e Merge pull request #49 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2023-10-23 20:45:38 +02:00
pre-commit-ci[bot]
8f7e2d1bd1 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 23.9.1 → 23.10.0](https://github.com/psf/black/compare/23.9.1...23.10.0)
- [github.com/pre-commit/mirrors-mypy: v1.6.0 → v1.6.1](https://github.com/pre-commit/mirrors-mypy/compare/v1.6.0...v1.6.1)
2023-10-23 17:28:09 +00:00
Jonas Bushart
44e5adf23b Merge pull request #48 from actions-rust-lang/pre-commit-ci-update-config 2023-10-16 20:58:20 +02:00
pre-commit-ci[bot]
c696842dcb [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.5.1 → v1.6.0](https://github.com/pre-commit/mirrors-mypy/compare/v1.5.1...v1.6.0)
2023-10-16 17:21:30 +00:00
Jonas Bushart
3852156fff Merge pull request #47 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2023-10-09 19:44:00 +02:00
pre-commit-ci[bot]
246a8329c9 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/pre-commit-hooks: v4.4.0 → v4.5.0](https://github.com/pre-commit/pre-commit-hooks/compare/v4.4.0...v4.5.0)
- [github.com/asottile/pyupgrade: v3.13.0 → v3.15.0](https://github.com/asottile/pyupgrade/compare/v3.13.0...v3.15.0)
2023-10-09 17:30:36 +00:00
Jonas Bushart
fad8f7b7af Update example workflow in readme 2023-10-03 18:56:13 +02:00
Jonas Bushart
799fa87586 Merge pull request #46 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2023-10-03 16:59:22 +02:00
pre-commit-ci[bot]
677ff77e8c [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.26.3 → 0.27.0](https://github.com/python-jsonschema/check-jsonschema/compare/0.26.3...0.27.0)
2023-10-02 20:14:51 +00:00
Jonas Bushart
0a72dd284e Merge pull request #44 from actions-rust-lang/dependabot/github_actions/actions/checkout-4 2023-10-01 21:59:47 +02:00
dependabot[bot]
672ca0693e Bump actions/checkout from 3 to 4
Bumps [actions/checkout](https://github.com/actions/checkout) from 3 to 4.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v3...v4)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-10-01 18:45:53 +00:00
Jonas Bushart
7feab04f1a Merge pull request #43 from actions-rust-lang/pre-commit-ci-update-config 2023-09-25 23:56:42 +02:00
pre-commit-ci[bot]
feb1d0bdca [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.10.1 → v3.13.0](https://github.com/asottile/pyupgrade/compare/v3.10.1...v3.13.0)
2023-09-25 20:19:19 +00:00
Jonas Bushart
7e6721cf40 Merge pull request #42 from actions-rust-lang/pre-commit-ci-update-config 2023-09-11 22:26:33 +02:00
pre-commit-ci[bot]
660e5d19a6 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 23.7.0 → 23.9.1](https://github.com/psf/black/compare/23.7.0...23.9.1)
2023-09-11 20:16:33 +00:00
Jonas Bushart
19016ced74 Merge pull request #41 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2023-08-28 22:27:17 +02:00
pre-commit-ci[bot]
4af958f59b [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.24.1 → 0.26.3](https://github.com/python-jsonschema/check-jsonschema/compare/0.24.1...0.26.3)
2023-08-28 19:43:54 +00:00
Jonas Bushart
2dc31fb5ef Add changelog entry 2023-08-23 19:17:52 +02:00
Jonas Bushart
ca4f182e86 Be more robust in handling missing data from RUSTSEC advisory
Closes #40
2023-08-23 19:16:59 +02:00
Jonas Bushart
19c45e9a43 Merge pull request #39 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2023-08-22 08:09:02 +02:00
pre-commit-ci[bot]
22e7edaffe [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.5.0 → v1.5.1](https://github.com/pre-commit/mirrors-mypy/compare/v1.5.0...v1.5.1)
2023-08-21 19:54:32 +00:00
Jonas Bushart
c367d7a394 Merge pull request #38 from actions-rust-lang/pre-commit-ci-update-config 2023-08-14 22:14:21 +02:00
pre-commit-ci[bot]
d8f9adf642 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.4.1 → v1.5.0](https://github.com/pre-commit/mirrors-mypy/compare/v1.4.1...v1.5.0)
- [github.com/python-jsonschema/check-jsonschema: 0.23.3 → 0.24.1](https://github.com/python-jsonschema/check-jsonschema/compare/0.23.3...0.24.1)
2023-08-14 19:51:41 +00:00
Jonas Bushart
2d2ada1a62 Merge pull request #37 from actions-rust-lang/pre-commit-ci-update-config 2023-07-31 22:18:40 +02:00
pre-commit-ci[bot]
73e05e72a7 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.9.0 → v3.10.1](https://github.com/asottile/pyupgrade/compare/v3.9.0...v3.10.1)
2023-07-31 20:02:47 +00:00
Jonas Bushart
ce625a3fb1 Merge pull request #36 from actions-rust-lang/pre-commit-ci-update-config 2023-07-17 22:39:17 +02:00
pre-commit-ci[bot]
0273520156 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 23.3.0 → 23.7.0](https://github.com/psf/black/compare/23.3.0...23.7.0)
- [github.com/python-jsonschema/check-jsonschema: 0.23.2 → 0.23.3](https://github.com/python-jsonschema/check-jsonschema/compare/0.23.2...0.23.3)
2023-07-17 20:01:12 +00:00
Jonas Bushart
01252679fb Merge pull request #35 from actions-rust-lang/pre-commit-ci-update-config 2023-07-10 22:08:25 +02:00
pre-commit-ci[bot]
0ea49bd8cb [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.8.0 → v3.9.0](https://github.com/asottile/pyupgrade/compare/v3.8.0...v3.9.0)
2023-07-10 19:43:24 +00:00
Jonas Bushart
b91ce6d80f Merge pull request #34 from actions-rust-lang/pre-commit-ci-update-config 2023-07-03 22:32:21 +02:00
pre-commit-ci[bot]
3f91ab5f83 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.7.0 → v3.8.0](https://github.com/asottile/pyupgrade/compare/v3.7.0...v3.8.0)
2023-07-03 19:38:34 +00:00
Jonas Bushart
debd2dd3cc Merge pull request #32 from actions-rust-lang/pre-commit-ci-update-config 2023-06-26 21:30:01 +02:00
pre-commit-ci[bot]
64f6d2e350 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.3.0 → v1.4.1](https://github.com/pre-commit/mirrors-mypy/compare/v1.3.0...v1.4.1)
2023-06-26 19:21:16 +00:00
Jonas Bushart
87ce76a59f Merge pull request #31 from actions-rust-lang/pre-commit-ci-update-config 2023-06-19 21:59:43 +02:00
pre-commit-ci[bot]
f3aaeb714e [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.6.0 → v3.7.0](https://github.com/asottile/pyupgrade/compare/v3.6.0...v3.7.0)
- [github.com/python-jsonschema/check-jsonschema: 0.23.1 → 0.23.2](https://github.com/python-jsonschema/check-jsonschema/compare/0.23.1...0.23.2)
2023-06-19 19:42:59 +00:00
Jonas Bushart
d13447f935 Merge pull request #30 from actions-rust-lang/pre-commit-ci-update-config 2023-06-12 22:00:31 +02:00
pre-commit-ci[bot]
bdd908fe01 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.4.0 → v3.6.0](https://github.com/asottile/pyupgrade/compare/v3.4.0...v3.6.0)
2023-06-12 19:25:25 +00:00
Jonas Bushart
3164457fe4 Merge pull request #29 from actions-rust-lang/pre-commit-ci-update-config 2023-06-05 21:15:19 +02:00
pre-commit-ci[bot]
023bfd076f [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/python-jsonschema/check-jsonschema: 0.23.0 → 0.23.1](https://github.com/python-jsonschema/check-jsonschema/compare/0.23.0...0.23.1)
2023-06-05 19:12:09 +00:00
Jonas Bushart
5e37004d2c Merge pull request #28 from actions-rust-lang/pre-commit-ci-update-config 2023-05-16 17:00:06 +02:00
pre-commit-ci[bot]
06034075ba [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.2.0 → v1.3.0](https://github.com/pre-commit/mirrors-mypy/compare/v1.2.0...v1.3.0)
2023-05-15 19:14:54 +00:00
Jonas Bushart
fe269d550e Update cargo-audit to 0.17.6 2023-05-12 22:05:27 +02:00
Jonas Bushart
b6da146557 Merge pull request #27 from actions-rust-lang/pre-commit-ci-update-config 2023-05-08 22:21:23 +02:00
pre-commit-ci[bot]
e661f5f79f [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.3.2 → v3.4.0](https://github.com/asottile/pyupgrade/compare/v3.3.2...v3.4.0)
- [github.com/python-jsonschema/check-jsonschema: 0.22.0 → 0.23.0](https://github.com/python-jsonschema/check-jsonschema/compare/0.22.0...0.23.0)
2023-05-08 19:32:55 +00:00
Jonas Bushart
6c5b44595d Merge pull request #26 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2023-05-01 23:08:15 +02:00
pre-commit-ci[bot]
b4f705152a [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.3.1 → v3.3.2](https://github.com/asottile/pyupgrade/compare/v3.3.1...v3.3.2)
2023-05-01 19:24:23 +00:00
Jonas Bushart
38e4be49ce Merge pull request #25 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2023-04-11 06:01:20 +03:00
pre-commit-ci[bot]
c93937eff7 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.1.1 → v1.2.0](https://github.com/pre-commit/mirrors-mypy/compare/v1.1.1...v1.2.0)
2023-04-10 19:18:55 +00:00
Jonas Bushart
b890df83b8 Merge pull request #24 from actions-rust-lang/pre-commit-ci-update-config 2023-04-03 22:12:59 +02:00
pre-commit-ci[bot]
8d89530feb [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 23.1.0 → 23.3.0](https://github.com/psf/black/compare/23.1.0...23.3.0)
2023-04-03 19:54:37 +00:00
Jonas Bushart
7e63792ca8 Update cargo-audit to 0.17.5 2023-03-24 20:14:05 +01:00
Jonas Bushart
229220ba5c Merge pull request #23 from actions-rust-lang/pre-commit-ci-update-config 2023-03-13 21:59:19 +01:00
pre-commit-ci[bot]
0fd4d6ceb9 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.0.1 → v1.1.1](https://github.com/pre-commit/mirrors-mypy/compare/v1.0.1...v1.1.1)
- [github.com/python-jsonschema/check-jsonschema: 0.21.0 → 0.22.0](https://github.com/python-jsonschema/check-jsonschema/compare/0.21.0...0.22.0)
2023-03-13 19:27:32 +00:00
Jonas Bushart
26cc152162 Merge pull request #22 from actions-rust-lang/pre-commit-ci-update-config 2023-02-20 20:16:44 +01:00
pre-commit-ci[bot]
839e077185 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v1.0.0 → v1.0.1](https://github.com/pre-commit/mirrors-mypy/compare/v1.0.0...v1.0.1)
2023-02-20 19:03:41 +00:00
Jonas Bushart
a4304b40f7 Check the syntax of GitHub Actions and Workflows files 2023-02-13 20:17:27 +01:00
Jonas Bushart
de4a880f36 Merge pull request #21 from actions-rust-lang/pre-commit-ci-update-config 2023-02-13 20:15:08 +01:00
pre-commit-ci[bot]
60557a6189 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v0.991 → v1.0.0](https://github.com/pre-commit/mirrors-mypy/compare/v0.991...v1.0.0)
2023-02-13 19:09:15 +00:00
Jonas Bushart
fc8955c20d Merge pull request #20 from actions-rust-lang/pre-commit-ci-update-config 2023-02-06 21:01:58 +01:00
pre-commit-ci[bot]
5e0c395775 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 22.12.0 → 23.1.0](https://github.com/psf/black/compare/22.12.0...23.1.0)
2023-02-06 19:35:04 +00:00
Jonas Bushart
362dc829f3 Merge pull request #19 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2023-01-30 21:12:36 +01:00
pre-commit-ci[bot]
ea1aefd179 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/PyCQA/isort: 5.11.4 → 5.12.0](https://github.com/PyCQA/isort/compare/5.11.4...5.12.0)
2023-01-30 19:23:47 +00:00
Jonas Bushart
0d6847edc7 Merge pull request #18 from actions-rust-lang/pre-commit-ci-update-config 2022-12-26 20:33:51 +01:00
pre-commit-ci[bot]
058839aa82 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/PyCQA/isort: v5.11.3 → 5.11.4](https://github.com/PyCQA/isort/compare/v5.11.3...5.11.4)
2022-12-26 18:55:00 +00:00
Jonas Bushart
165ccb4a64 Prepare new version to fix duplicate issues for yanked crates 2022-12-22 23:09:27 +01:00
Jonas Bushart
623cff7dbe Fix finding of existing issues, since the issue title format was expanded
Issues for yanked crates start with "Crate ... v..." not with
"RUSTSEC-". So the filter on the existing issues list was too strict,
not detecting the issue for yanked crates. This causes duplicate issues.
2022-12-22 22:44:56 +01:00
Jonas Bushart
2406ebfa1e Prepare new version v1.1.4
Closes #17
2022-12-22 22:00:04 +01:00
Jonas Bushart
bbbc43cd45 Add icon to markdown summary for yanked crates 2022-12-22 21:51:32 +01:00
Jonas Bushart
44f419d83a Handle that the advisory field is optional
If missing show a message that the crate is yanked
2022-12-22 21:42:26 +01:00
Jonas Bushart
bf3d0bcece Add some debug statements
This should make future debugging requests easier, since the cargo audit
command and the resulting JSON are directly accessible.
2022-12-22 21:33:06 +01:00
Jonas Bushart
cf4c31eba1 Merge pull request #16 from actions-rust-lang/pre-commit-ci-update-config 2022-12-19 19:43:10 +01:00
pre-commit-ci[bot]
13b59a5eab [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/PyCQA/isort: 5.10.1 → v5.11.3](https://github.com/PyCQA/isort/compare/5.10.1...v5.11.3)
2022-12-19 18:33:35 +00:00
Jonas Bushart
502e7e5028 Merge pull request #15 from actions-rust-lang/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2022-12-12 20:01:18 +01:00
pre-commit-ci[bot]
8ee9b53721 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/psf/black: 22.10.0 → 22.12.0](https://github.com/psf/black/compare/22.10.0...22.12.0)
- [github.com/asottile/pyupgrade: v3.3.0 → v3.3.1](https://github.com/asottile/pyupgrade/compare/v3.3.0...v3.3.1)
2022-12-12 18:48:16 +00:00
Jonas Bushart
2c37721442 Add timeout arguments to network functions
This fixes a pylint warning
2022-12-05 22:22:46 +00:00
Jonas Bushart
65677fab72 Release version with caching fixes 2022-12-05 22:04:42 +00:00
Jonas Bushart
8de7e6de94 Remove duplicate bin/ 2022-12-05 21:00:24 +00:00
Jonas Bushart
a1194263c1 Fix the path for cache action 2022-12-05 20:06:33 +00:00
Jonas Bushart
88907a355a Merge pull request #14 from actions-rust-lang/pre-commit-ci-update-config 2022-12-05 19:45:55 +01:00
pre-commit-ci[bot]
568294585d [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.2.2 → v3.3.0](https://github.com/asottile/pyupgrade/compare/v3.2.2...v3.3.0)
2022-12-05 18:31:12 +00:00
Jonas Bushart
ec48ef0b45 Merge pull request #13 from actions-rust-lang/pre-commit-ci-update-config 2022-11-28 21:14:03 +01:00
pre-commit-ci[bot]
b8f4057e9c [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/pre-commit-hooks: v4.3.0 → v4.4.0](https://github.com/pre-commit/pre-commit-hooks/compare/v4.3.0...v4.4.0)
2022-11-28 19:00:41 +00:00
Jonas Bushart
92881e10cb Merge pull request #12 from actions-rust-lang/pre-commit-ci-update-config 2022-11-21 20:17:04 +01:00
pre-commit-ci[bot]
ece2fac1af [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/pre-commit/mirrors-mypy: v0.990 → v0.991](https://github.com/pre-commit/mirrors-mypy/compare/v0.990...v0.991)
2022-11-21 18:16:37 +00:00
Jonas Bushart
16d3c44a77 Merge pull request #11 from actions-rust-lang/pre-commit-ci-update-config 2022-11-14 19:34:37 +01:00
pre-commit-ci[bot]
3164ded2e4 [pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/asottile/pyupgrade: v3.2.0 → v3.2.2](https://github.com/asottile/pyupgrade/compare/v3.2.0...v3.2.2)
- [github.com/pre-commit/mirrors-mypy: v0.982 → v0.990](https://github.com/pre-commit/mirrors-mypy/compare/v0.982...v0.990)
2022-11-14 18:23:14 +00:00
7 changed files with 340 additions and 98 deletions

View File

@@ -8,4 +8,6 @@ updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "monthly"
interval: "weekly"
cooldown:
default-days: 7

View File

@@ -15,7 +15,7 @@ jobs:
permissions:
contents: write
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v6
- name: Get version from tag
id: tag_name
run: |

View File

@@ -1,10 +1,10 @@
repos:
- repo: https://github.com/psf/black
rev: 22.10.0
- repo: https://github.com/psf/black-pre-commit-mirror
rev: 25.12.0
hooks:
- id: black
- repo: https://github.com/pre-commit/pre-commit-hooks
rev: v4.3.0
rev: v6.0.0
hooks:
- id: check-ast
- id: check-case-conflict
@@ -14,19 +14,25 @@ repos:
- id: end-of-file-fixer
- id: trailing-whitespace
- repo: https://github.com/PyCQA/isort
rev: 5.10.1
rev: 7.0.0
# https://github.com/psf/black/blob/main/docs/guides/using_black_with_other_tools.md
hooks:
- id: isort
args: ["--profile=black"]
- repo: https://github.com/asottile/pyupgrade
rev: v3.2.0
rev: v3.21.2
hooks:
- id: pyupgrade
args: ["--py37-plus"]
- repo: https://github.com/pre-commit/mirrors-mypy
rev: v0.982
rev: v1.19.1
hooks:
- id: mypy
additional_dependencies:
- types-requests
- repo: https://github.com/python-jsonschema/check-jsonschema
rev: 0.36.0
hooks:
- id: check-dependabot
- id: check-github-actions
- id: check-github-workflows

View File

@@ -7,6 +7,91 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
## [Unreleased]
## [1.2.6] - 2025-11-22
* Update `cargo-audit` to 0.22.0
## [1.2.5] - 2025-10-09
* Pin the version of `actions/cache` to commit hash by @Gronner in #122
## [1.2.4] - 2025-03-03
* Update `cargo-audit` to 0.21.2
## [1.2.3] - 2024-12-17
* Show a better error message when running "cargo audit" fails #98
## [1.2.2] - 2024-11-06
* Update `cargo-audit` to 0.21.0
## [1.2.1] - 2024-07-31
* Temporarily remove `--locked` from the install instructions again, since cargo-audit relies on an old version of `time` that is incompatible with Rust 1.80.
## [1.2.0] - 2024-03-05
* feat: add --locked to cargo install cargo-audit by @lwshang in #72
* Add working directory input to configure where cargo audit executes by @jonasbb in #78
## [1.1.14] - 2024-02-18
* Update `cargo-audit` to 0.20.0
## [1.1.13] - 2024-02-03
* Update `cargo-audit` to 0.19.0
## [1.1.12] - 2024-01-20
* Fix default of `file` argument to make it work again for repositories without `Cargo.lock` checked in.
## [1.1.11] - 2024-01-18
* Allow specifying the path to the `Cargo.lock` file, in case it is not in the root of the repository (#55)
* Update the example in the README, to have the correct permissions for private repositories.
## [1.1.10] - 2023-11-02
* Fix running the action, by using the correct version of the cache action.
## [1.1.9] - 2023-11-01
* Update `cargo-audit` to 0.18.3
## [1.1.8] - 2023-08-23
* Handle missing data in advisories better to prevent crashing (#40)
## [1.1.7] - 2023-05-12
* Update `cargo-audit` to 0.17.6
## [1.1.6] - 2023-03-24
* Update `cargo-audit` to 0.17.5
## [1.1.5] - 2022-12-22
* Fix duplicate issues for yanked crates.
The previous version introduced a bug where existing issues were not properly detected.
This only affected issues for yanked crates.
Now duplicate issues will no longer be created.
## [1.1.4] - 2022-12-22
* Handle warnings without any associated advisory.
This occurs for yanked crates, where the `advisory` field is `null` in the JSON output.
Now a message is shown that the crate and version is yanked.
## [1.1.3] - 2022-12-05
* Fix the path to the cargo installation directory to fix caching.
## [1.1.2] - 2022-11-09
### Changed

View File

@@ -1,6 +1,6 @@
# Audit Rust dependencies using the RustSec Advisory DB
Audit your Rust dependencies using [cargo audit] and the [RustSec Advisory DB]. The action creates a summary with all vulnerabilieties. It can create issues for each of the found vulnerabilities.
Audit your Rust dependencies using [cargo audit] and the [RustSec Advisory DB]. The action creates a summary with all vulnerabilities. It can create issues for each of the found vulnerabilities.
Execution Summary:
@@ -20,21 +20,20 @@ on:
- '**/Cargo.lock'
# Run if the configuration file changes
- '**/audit.toml'
# Rerun periodicly to pick up new advisories
# Rerun periodically to pick up new advisories
schedule:
- cron: '0 0 * * *'
# Run manually
workflow_dispatch:
permissions: read-all
jobs:
audit:
runs-on: ubuntu-latest
permissions:
contents: read
issues: write
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v4
- uses: actions-rust-lang/audit@v1
name: Audit Rust Dependencies
with:
@@ -45,17 +44,31 @@ jobs:
## Inputs
All inputs are optional.
Consider adding a [`audit.toml` configuration file] to your repository for further configurations.
Consider adding an [`audit.toml` configuration file] to your repository for further configurations.
cargo audit supports multiple warning types, such as unsound code or yanked crates.
Configuration is only possible via the `informational_warnings` parameter in the configuration file ([#318](https://github.com/rustsec/rustsec/issues/318)).
Setting `denyWarnings` to true will also enable these warnings, but each warning is upgraded to an error.
| Name | Description | Default |
| -------------- | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------ |
| `TOKEN` | The GitHub access token to allow us to retrieve, create and update issues (automatically set). | `github.token` |
| `denyWarnings` | Any warnings generated will be treated as an error and fail the action. | false |
| `ignore` | A comma separated list of Rustsec IDs to ignore. | |
| `createIssues` | Create/Update issues for each found vulnerability. By default only on `main` or `master` branch. | `github.ref == 'refs/heads/master' \|\| github.ref == 'refs/heads/main'` |
| Name | Description | Default |
| ------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------ |
| `TOKEN` | The GitHub access token to allow us to retrieve, create and update issues (automatically set). | `github.token` |
| `denyWarnings` | Any warnings generated will be treated as an error and fail the action. | false |
| `file` | The path to the Cargo.lock file to inspect file. | |
| `ignore` | A comma separated list of Rustsec IDs to ignore. | |
| `createIssues` | Create/Update issues for each found vulnerability. By default only on `main` or `master` branch. | `github.ref == 'refs/heads/master' \|\| github.ref == 'refs/heads/main'` |
| `workingDirectory` | Run `cargo audit` from the given working directory | |
## Dependencies
The action works best on the GitHub-hosted runners, but can work on self-hosted ones too, provided the necessary dependencies are available.
PRs to add support for more environments are welcome.
* bash
* Python 3.9+
* requests
* Rust stable
* cargo
* use node actions
## License

View File

@@ -14,6 +14,10 @@ inputs:
description: "Any warnings generated will be treated as an error and fail the action"
required: false
default: "false"
file:
description: "The path to the Cargo.lock file to inspect"
required: false
default: ""
ignore:
description: "A comma separated list of Rustsec IDs to ignore"
required: false
@@ -22,23 +26,31 @@ inputs:
description: Create/Update issues for each found vulnerability.
required: false
default: "${{ github.ref == 'refs/heads/master' || github.ref == 'refs/heads/main' }}"
workingDirectory:
description: "Run `cargo audit` from the given working directory"
required: false
default: ""
runs:
using: composite
steps:
- uses: actions/cache@v3
- name: Identify cargo installation directory
run: echo "cargohome=${CARGO_HOME:-$HOME/.cargo}" >> $GITHUB_OUTPUT
shell: bash
id: cargo-home
- uses: actions/cache@9255dc7a253b0ccc959486e2bca901246202afeb # v5.0.1
id: cache
with:
path: |
${{ env.CARGO_HOME }}/.cargo/bin/cargo-audit*
${{ env.CARGO_HOME }}/.cargo/.crates.toml
${{ env.CARGO_HOME }}/.cargo/.crates2.json
key: cargo-audit-v0.17.4
${{ steps.cargo-home.outputs.cargohome }}/bin/cargo-audit*
${{ steps.cargo-home.outputs.cargohome }}/.crates.toml
${{ steps.cargo-home.outputs.cargohome }}/.crates2.json
key: cargo-audit-v0.22.0
- name: Install cargo-audit
if: steps.cache.outputs.cache-hit != 'true'
# Update both this version number and the cache key
run: cargo install cargo-audit --vers 0.17.4 --no-default-features
run: cargo install cargo-audit --vers 0.22.0 --no-default-features
shell: bash
- run: |
@@ -48,7 +60,9 @@ runs:
env:
INPUT_CREATE_ISSUES: ${{ inputs.createIssues }}
INPUT_DENY_WARNINGS: ${{ inputs.denyWarnings }}
INPUT_FILE: ${{ inputs.file }}
INPUT_IGNORE: ${{ inputs.ignore }}
INPUT_TOKEN: ${{ inputs.TOKEN }}
INPUT_WORKING_DIRECTORY: ${{ inputs.workingDirectory }}
PYTHONPATH: ${{ github.action_path }}
REPO: ${{ github.repository }}

266
audit.py
View File

@@ -7,10 +7,33 @@ from typing import Any, Dict, List, Optional, Union
import requests
# GitHub API CLient copied and adapted from
# GitHub API Client copied and adapted from
# https://github.com/alstr/todo-to-issue-action/blob/25c80e9c4999d107bec208af49974d329da26370/main.py
# Originally licensed under MIT license
TIMEOUT = 30
"""Timeout in seconds for requests methods"""
NEWLINE = "\n"
"""Definition of newline"""
def debug(message: str) -> None:
"""Print a debug message to the GitHub Action log"""
print(f"""::debug::{message.replace(NEWLINE, " ")}""")
def error(message: str) -> None:
"""Print an error message to the GitHub Action log"""
print(f"""::error::{message.replace(NEWLINE, " ")}""")
def group(title: str, message: str) -> None:
"""Print an expandable group message to the GitHub Action log"""
print(f"::group::{title}")
print(message)
print("::endgroup::")
class Issue:
"""Basic Issue model for collecting the necessary info to send to GitHub."""
@@ -21,7 +44,7 @@ class Issue:
labels: List[str],
assignees: List[str],
body: str,
rustsec_id: str,
rustsec_id: str, # Should be the start of the title
) -> None:
self.title = title
self.labels = labels
@@ -59,62 +82,91 @@ class Entry:
self.entry_type = entry_type
self.warning_type = warning_type
def id(self) -> str:
"""
Return the ID of the entry.
"""
# IMPORTANT: Coordinate this value with the `_get_existing_issues` method below.
# Any value returned here must also be present in the filtering there, since the id will be used in the issue title.
advisory = self.entry.get("advisory", None)
if advisory:
return advisory["id"]
else:
return f"Crate {self.entry['package']['name']} {self.entry['package']['version']}"
def _entry_table(self) -> str:
advisory = self.entry["advisory"]
advisory = self.entry.get("advisory", None)
table = []
table.append(("Details", ""))
table.append(("---", "---"))
table.append(("Package", f"`{advisory['package']}`"))
table.append(("Version", f"`{self.entry['package']['version']}`"))
if self.warning_type is not None:
table.append(("Warning", str(self.warning_type)))
table.append(("URL", advisory["url"]))
table.append(
(
"Patched Versions",
" OR ".join(self.entry["versions"]["patched"])
if len(self.entry["versions"]["patched"]) > 0
else "n/a",
)
)
if len(self.entry["versions"]["unaffected"]) > 0:
if advisory:
table = []
table.append(("Details", ""))
table.append(("---", "---"))
table.append(("Package", f"`{advisory['package']}`"))
table.append(("Version", f"`{self.entry['package']['version']}`"))
if self.warning_type is not None:
table.append(("Warning", str(self.warning_type)))
table.append(("URL", advisory["url"]))
table.append(
(
"Unaffected Versions",
" OR ".join(self.entry["versions"]["unaffected"]),
)
)
if len(advisory["aliases"]) > 0:
table.append(
(
"Aliases",
", ".join(
Entry._md_autolink_advisory_id(advisory_id)
for advisory_id in advisory["aliases"]
"Patched Versions",
(
" OR ".join(self.entry["versions"]["patched"])
if len(self.entry["versions"]["patched"]) > 0
else "n/a"
),
)
)
if len(advisory["related"]) > 0:
table.append(
(
"Related Advisories",
", ".join(
Entry._md_autolink_advisory_id(advisory_id)
for advisory_id in advisory["related"]
),
if len(self.entry["versions"]["unaffected"]) > 0:
table.append(
(
"Unaffected Versions",
" OR ".join(self.entry["versions"]["unaffected"]),
)
)
if len(advisory["aliases"]) > 0:
table.append(
(
"Aliases",
", ".join(
Entry._md_autolink_advisory_id(advisory_id)
for advisory_id in advisory["aliases"]
),
)
)
if len(advisory["related"]) > 0:
table.append(
(
"Related Advisories",
", ".join(
Entry._md_autolink_advisory_id(advisory_id)
for advisory_id in advisory["related"]
),
)
)
)
table_parts = []
for row in table:
table_parts.append("| ")
table_parts.append(row[0])
table_parts.append(" | ")
table_parts.append(row[1])
table_parts.append(" |\n")
table_parts = []
for row in table:
table_parts.append("| ")
if row[0] is not None:
table_parts.append(row[0])
table_parts.append(" | ")
if row[1] is not None:
table_parts.append(row[1])
else:
table_parts.append("n/a")
table_parts.append(" |\n")
return "".join(table_parts)
return "".join(table_parts)
else:
# There is no advisory.
# This occurs when a yanked version is detected.
name = self.entry["package"]["name"]
return f"""{self.id()} is yanked.
Switch to a different version of `{name}` to resolve this issue.
"""
@classmethod
def _md_autolink_advisory_id(cls, advisory_id: str) -> str:
@@ -132,37 +184,64 @@ class Entry:
return advisory_id
def format_as_markdown(self) -> str:
advisory = self.entry["advisory"]
advisory = self.entry.get("advisory", None)
entry_table = self._entry_table()
# Replace the @ with a ZWJ to avoid triggering markdown autolinks
# Otherwise GitHub will interpret the @ as a mention
description = advisory["description"].replace("@", "@\u200d")
if advisory:
entry_table = self._entry_table()
# Replace the @ with a ZWJ to avoid triggering markdown autolinks
# Otherwise GitHub will interpret the @ as a mention
description = advisory["description"].replace("@", "@\u200d")
md = f"""## {self.entry_type.icon()} {advisory['id']}: {advisory['title']}
md = f"""## {self.entry_type.icon()} {advisory['id']}: {advisory['title']}
{entry_table}
{description}
"""
return md
return md
else:
# There is no advisory.
# This occurs when a yanked version is detected.
name = self.entry["package"]["name"]
return f"""## {self.entry_type.icon()} {self.id()} is yanked.
Switch to a different version of `{name}` to resolve this issue.
"""
def format_as_issue(self, labels: List[str], assignees: List[str]) -> Issue:
advisory = self.entry["advisory"]
advisory = self.entry.get("advisory", None)
entry_table = self._entry_table()
if advisory:
entry_table = self._entry_table()
title = f"{advisory['id']}: {advisory['title']}"
body = f"""{entry_table}
title = f"{self.id()}: {advisory['title']}"
body = f"""{entry_table}
{advisory['description']}"""
return Issue(
title=title,
labels=labels,
assignees=assignees,
body=body,
rustsec_id=advisory["id"],
)
return Issue(
title=title,
labels=labels,
assignees=assignees,
body=body,
rustsec_id=self.id(),
)
else:
# There is no advisory.
# This occurs when a yanked version is detected.
name = self.entry["package"]["name"]
title = f"{self.id()} is yanked"
body = (
f"""Switch to a different version of `{name}` to resolve this issue."""
)
return Issue(
title=title,
labels=labels,
assignees=assignees,
body=body,
rustsec_id=self.id(),
)
class GitHubClient:
@@ -183,6 +262,10 @@ class GitHubClient:
# Retrieve the existing repo issues now so we can easily check them later.
self._get_existing_issues()
debug("Existing issues:")
for issue in self.existing_issues:
debug(f"* {issue['title']}")
def _get_existing_issues(self, page: int = 1) -> None:
"""Populate the existing issues list."""
params: Dict[str, Union[str, int]] = {
@@ -190,8 +273,9 @@ class GitHubClient:
"page": page,
"state": "open",
}
debug(f"Fetching existing issues from GitHub: {page=}")
list_issues_request = requests.get(
self.issues_url, headers=self.issue_headers, params=params
self.issues_url, headers=self.issue_headers, params=params, timeout=TIMEOUT
)
if list_issues_request.status_code == 200:
self.existing_issues.extend(
@@ -199,6 +283,7 @@ class GitHubClient:
issue
for issue in list_issues_request.json()
if issue["title"].startswith("RUSTSEC-")
or issue["title"].startswith("Crate ")
]
)
links = list_issues_request.links
@@ -208,6 +293,7 @@ class GitHubClient:
def create_issue(self, issue: Issue) -> Optional[int]:
"""Create a dict containing the issue details and send it to GitHub."""
title = issue.title
debug(f"Creating issue: {title=}")
# Check if the current issue already exists - if so, skip it.
# The below is a simple and imperfect check based on the issue title.
@@ -226,9 +312,14 @@ class GitHubClient:
existing_issue["url"],
headers=self.issue_headers,
data=json.dumps(body),
timeout=TIMEOUT,
)
return update_request.status_code
debug(
f"""No existing issue found for "{issue.rustsec_id}". Creating new issue."""
)
new_issue_body = {"title": title, "body": issue.body, "labels": issue.labels}
# We need to check if any assignees/milestone specified exist, otherwise issue creation will fail.
@@ -236,7 +327,9 @@ class GitHubClient:
for assignee in issue.assignees:
assignee_url = f"{self.repos_url}{self.repo}/assignees/{assignee}"
assignee_request = requests.get(
url=assignee_url, headers=self.issue_headers
url=assignee_url,
headers=self.issue_headers,
timeout=TIMEOUT,
)
if assignee_request.status_code == 204:
valid_assignees.append(assignee)
@@ -248,6 +341,7 @@ class GitHubClient:
url=self.issues_url,
headers=self.issue_headers,
data=json.dumps(new_issue_body),
timeout=TIMEOUT,
)
return new_issue_request.status_code
@@ -255,7 +349,10 @@ class GitHubClient:
def close_issue(self, issue: Dict[str, Any]) -> int:
body = {"state": "closed"}
close_request = requests.patch(
issue["url"], headers=self.issue_headers, data=json.dumps(body)
issue["url"],
headers=self.issue_headers,
data=json.dumps(body),
timeout=TIMEOUT,
)
return close_request.status_code
@@ -317,13 +414,38 @@ def run() -> None:
extra_args.append("--deny")
extra_args.append("warnings")
if os.environ["INPUT_FILE"] != "":
extra_args.append("--file")
extra_args.append(os.environ["INPUT_FILE"])
working_directory = None
if os.environ["INPUT_WORKING_DIRECTORY"] != "":
working_directory = os.environ["INPUT_WORKING_DIRECTORY"]
audit_cmd = ["cargo", "audit", "--json"] + extra_args + ignore_args
debug(f"Running command: {audit_cmd}")
completed = subprocess.run(
["cargo", "audit", "--json"] + extra_args + ignore_args,
audit_cmd,
cwd=working_directory,
capture_output=True,
text=True,
check=False,
)
data = json.loads(completed.stdout)
debug(f"Command return code: {completed.returncode}")
debug(f"Command output: {completed.stdout}")
debug(f"Command error: {completed.stderr}")
try:
data = json.loads(completed.stdout)
except json.decoder.JSONDecodeError as _:
error(
f"cargo audit did not produce any JSON output. Exit code: {completed.returncode}"
)
group(
"cargo audit output",
f"""stdout:\n{completed.stdout}\n\n\nstderr:\n{completed.stderr}""",
)
sys.exit(2)
summary = create_summary(data)
entries = create_entries(data)
@@ -356,7 +478,7 @@ def run() -> None:
num_existing_issues = len(gh_client.existing_issues)
for entry in entries:
for ex_issue in gh_client.existing_issues:
if ex_issue["title"].startswith(entry.entry["advisory"]["id"]):
if ex_issue["title"].startswith(entry.id()):
gh_client.existing_issues.remove(ex_issue)
num_old_issues = len(gh_client.existing_issues)
print(