Files
DeepSeek-TUI/.github/workflows/security-audit.yml
Sun Zhenyuan ac214fd75b ci: add RustSec security audit and cargo-deny checks
Add security audit infrastructure using RustSec advisory database:

- .github/workflows/security-audit.yml: runs cargo-audit to scan
  Cargo.lock for known vulnerabilities
- .github/workflows/cargo-deny.yml: checks advisories, dependency
  bans, licenses, and sources
- audit.toml: cargo-audit configuration
- deny.toml: cargo-deny configuration with allowed licenses
- README.md: add Security audit and cargo-deny status badges
2026-07-10 11:26:05 +08:00

32 lines
623 B
YAML

name: Security audit
permissions: {}
on:
pull_request:
paths:
- '.github/workflows/security-audit.yml'
- '**/Cargo.toml'
- '**/Cargo.lock'
- '**/audit.toml'
push:
branches: [main, master]
schedule:
# Run weekly on Monday at 06:31 UTC
- cron: '31 6 * * 1'
env:
CARGO_TERM_COLOR: always
jobs:
self-audit:
name: cargo-audit
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
- name: Install cargo-audit
run: cargo install cargo-audit
- name: Run cargo audit
run: cargo audit