Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 24 additions & 0 deletions .cargo/audit.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# Configuration for `cargo audit`, run by the weekly cron in
# .github/workflows/crons.yml. See:
# https://github.com/rustsec/rustsec/blob/main/cargo-audit/audit.toml.example

[advisories]
ignore = [
# RUSTSEC-2022-0040: multiple soundness issues in `owning_ref`.
#
# Not reachable in any build we produce. `owning_ref` enters Cargo.lock only
# as an *optional* dependency of `lock_api`, which is reached three ways:
# `parking_lot` 0.12 and `dashmap` 6 (transitively), and
# `shuttle-parking_lot-impl` (directly). In every case pulling in
# `owning_ref` requires the non-default `owning_ref` feature, which nothing
# in this workspace enables. `cargo tree -i owning_ref --workspace` reports
# no match, confirming it is absent from the resolved build graph; `cargo
# audit` flags it anyway because it scans the lockfile, which records
# optional dependencies whether or not their feature is activated.
#
# The advisory has no fixed upgrade available, so it cannot be resolved by
# bumping. Revisit if `lock_api` drops the `owning_ref` dependency, or if
# this workspace ever enables the `owning_ref` feature by default -- at that
# point the code would genuinely be exposed and this entry must be removed.
"RUSTSEC-2022-0040",
]
2 changes: 1 addition & 1 deletion .github/workflows/bench.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ jobs:
runs-on: ubuntu-latest
continue-on-error: true # This step will not fail the job if it errors
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v5
- name: Install Rust
run: rustup update stable
- uses: boa-dev/criterion-compare-action@v3
Expand Down
40 changes: 35 additions & 5 deletions .github/workflows/crons.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,9 @@
name: Cron jobs

# Least privilege by default. Note that naming any scope here implicitly sets
# every unnamed scope to `none`, so jobs needing more must opt in explicitly.
permissions:
contents: write
contents: read

on:
push:
Expand All @@ -13,21 +16,42 @@ on:
jobs:
audit:
runs-on: ubuntu-latest
# See the note on the `beta` job below.
permissions:
contents: read
issues: write
steps:
- uses: actions/checkout@v2
- uses: actions/checkout@v5
- name: Install Rust
run: rustup update stable
- name: Install Audit
run: cargo install cargo-audit
- name: cargo audit
run: cargo audit
# Uses its own label so this is tracked separately from the `beta` job's
# notification: a new advisory and a beta toolchain regression are
# unrelated failures with unrelated fixes, and should not share an issue
# thread.
- name: Notify failed build
uses: drivendataorg/failed-build-issue-action@v1
if: failure()
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
label-name: "audit failed"
title-template: "Failed cargo audit: {{workflow}}"

# Runs Clippy, fmt, doc and tests on beta.
# Exists to not get "caught off guard" by new Rust versions bringing new clippies.
beta:
runs-on: ubuntu-latest
# `issues: write` is required by the "Notify failed build" step below, which
# opens an issue when this job fails. Job-level permissions replace the
# top-level block outright, so `contents: read` has to be restated here.
permissions:
contents: read
issues: write
steps:
- uses: actions/checkout@v2
- uses: actions/checkout@v5
- name: Install Rust
run: rustup update beta
- name: Default to beta
Expand All @@ -48,8 +72,14 @@ jobs:
run: cargo nextest run --release --workspace
- name: cargo test --doc
run: cargo test --release --doc --workspace
# Requires v1.3.0 or newer: earlier releases declare `runs.using: node20`,
# and Node 20 is removed from the runners on 2026-09-16. The action also
# moved from jayqi/ to drivendataorg/; the old path still redirects, but
# naming the canonical owner avoids depending on that.
- name: Notify failed build
uses: jayqi/failed-build-issue-action@v1
if: failure()
uses: drivendataorg/failed-build-issue-action@v1
if: failure()
with:
# Optional as of v1.3.0, which defaults it to `github.token`, but kept
# explicit to keep the token this step uses obvious at the call site.
github-token: ${{ secrets.GITHUB_TOKEN }}
6 changes: 5 additions & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
name: Release
permissions:
contents: read

on:
push:
branches: [main]
Expand All @@ -18,7 +22,7 @@ jobs:
name: Benchmarks (with vector clocks)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v5
- name: Install Rust
run: rustup update stable
- name: cargo bench
Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ jobs:
name: Tests
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v5
- name: Install Rust
run: rustup update stable
- name: Install nextest
Expand All @@ -34,7 +34,7 @@ jobs:
name: rustfmt
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v5
- name: Install Rust
run: rustup update stable
- name: Install rustfmt
Expand All @@ -46,19 +46,19 @@ jobs:
name: Clippy
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v5
- name: Install Rust
run: rustup update stable
- name: Install clippy
run: rustup component add rustfmt
run: rustup component add clippy
- name: clippy
run: cargo clippy --all-targets -- -D clippy::all

docs:
name: Docs
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v5
- name: Install Rust
run: rustup update stable
- name: cargo doc
Expand Down
Loading