ci(security): enforce Rust advisory policy
This commit is contained in:
@@ -52,6 +52,9 @@ jobs:
|
|||||||
- name: Audit source file size
|
- name: Audit source file size
|
||||||
run: scripts/audit_source_lines.sh
|
run: scripts/audit_source_lines.sh
|
||||||
|
|
||||||
|
- name: Verify Rust advisory exception boundaries
|
||||||
|
run: scripts/verify_rust_advisory_exceptions.sh
|
||||||
|
|
||||||
- name: Verify macOS bundle metadata
|
- name: Verify macOS bundle metadata
|
||||||
run: scripts/verify_macos_bundle_metadata.sh
|
run: scripts/verify_macos_bundle_metadata.sh
|
||||||
|
|
||||||
@@ -83,6 +86,19 @@ jobs:
|
|||||||
test -x target/distribution/ely-browser/ely_app
|
test -x target/distribution/ely-browser/ely_app
|
||||||
test -x target/distribution/ely-browser/ely_servo_sidecar
|
test -x target/distribution/ely-browser/ely_servo_sidecar
|
||||||
|
|
||||||
|
rust-advisories:
|
||||||
|
name: Rust dependency advisories
|
||||||
|
uses: google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@9a498708959aeaef5ef730655706c5a1df1edbc2 # v2.3.8
|
||||||
|
permissions:
|
||||||
|
actions: read
|
||||||
|
contents: read
|
||||||
|
with:
|
||||||
|
scan-args: |-
|
||||||
|
--lockfile=./Cargo.lock
|
||||||
|
--config=./osv-scanner.toml
|
||||||
|
upload-sarif: false
|
||||||
|
fail-on-vuln: true
|
||||||
|
|
||||||
portable:
|
portable:
|
||||||
name: Portable app (${{ matrix.os }})
|
name: Portable app (${{ matrix.os }})
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
@@ -122,6 +138,7 @@ jobs:
|
|||||||
scripts/create_macos_app_bundle.sh
|
scripts/create_macos_app_bundle.sh
|
||||||
scripts/create_native_distribution.sh
|
scripts/create_native_distribution.sh
|
||||||
scripts/release_build_env.sh
|
scripts/release_build_env.sh
|
||||||
|
scripts/verify_rust_advisory_exceptions.sh
|
||||||
scripts/verify_release_artifacts.sh
|
scripts/verify_release_artifacts.sh
|
||||||
|
|
||||||
- name: Build native distribution
|
- name: Build native distribution
|
||||||
|
|||||||
@@ -0,0 +1,67 @@
|
|||||||
|
[[IgnoredVulns]]
|
||||||
|
id = "RUSTSEC-2023-0071"
|
||||||
|
ignoreUntil = 2026-10-15
|
||||||
|
reason = "Vendored RSA returns before the shared private exponent primitive; unit and WebCrypto tests enforce the gate while RUSTSEC-2023-0071 has no patched release."
|
||||||
|
|
||||||
|
[[PackageOverrides]]
|
||||||
|
name = "quick-xml"
|
||||||
|
version = "0.30.0"
|
||||||
|
ecosystem = "crates.io"
|
||||||
|
vulnerability.ignore = true
|
||||||
|
effectiveUntil = 2026-10-15
|
||||||
|
reason = "Workspace and release feature graphs omit GPUI screen-capture; this optional zed-scap/xcb parser remains lock-only."
|
||||||
|
|
||||||
|
[[IgnoredVulns]]
|
||||||
|
id = "RUSTSEC-2025-0052"
|
||||||
|
ignoreUntil = 2026-10-15
|
||||||
|
reason = "Maintenance-status advisory in GPUI's zed-async-tar transport dependency; migrate with the next GPUI transport refresh."
|
||||||
|
|
||||||
|
[[IgnoredVulns]]
|
||||||
|
id = "RUSTSEC-2025-0141"
|
||||||
|
ignoreUntil = 2026-10-15
|
||||||
|
reason = "Maintenance-status advisory in Servo's WebRender serialization dependency; migrate with the next Servo/WebRender refresh."
|
||||||
|
|
||||||
|
[[IgnoredVulns]]
|
||||||
|
id = "RUSTSEC-2024-0384"
|
||||||
|
ignoreUntil = 2026-10-15
|
||||||
|
reason = "Maintenance-status advisory inherited from the pinned UI and engine stack; migrate with the next upstream stack refresh."
|
||||||
|
|
||||||
|
[[IgnoredVulns]]
|
||||||
|
id = "RUSTSEC-2024-0436"
|
||||||
|
ignoreUntil = 2026-10-15
|
||||||
|
reason = "Maintenance-status advisory inherited from the pinned UI and engine stack; migrate with the next upstream stack refresh."
|
||||||
|
|
||||||
|
[[IgnoredVulns]]
|
||||||
|
id = "RUSTSEC-2025-0134"
|
||||||
|
ignoreUntil = 2026-10-15
|
||||||
|
reason = "Maintenance-status advisory in Servo's TLS parsing dependency; migrate with the next Servo networking refresh."
|
||||||
|
|
||||||
|
[[IgnoredVulns]]
|
||||||
|
id = "RUSTSEC-2026-0192"
|
||||||
|
ignoreUntil = 2026-10-15
|
||||||
|
reason = "Maintenance-status advisory across pinned GPUI and Servo font stacks; migrate with their coordinated font dependency refresh."
|
||||||
|
|
||||||
|
[[IgnoredVulns]]
|
||||||
|
id = "RUSTSEC-2025-0081"
|
||||||
|
ignoreUntil = 2026-10-15
|
||||||
|
reason = "Maintenance-status advisory in Servo's pinned Unicode stack; migrate with the next Servo Unicode refresh."
|
||||||
|
|
||||||
|
[[IgnoredVulns]]
|
||||||
|
id = "RUSTSEC-2025-0075"
|
||||||
|
ignoreUntil = 2026-10-15
|
||||||
|
reason = "Maintenance-status advisory in Servo's pinned Unicode stack; migrate with the next Servo Unicode refresh."
|
||||||
|
|
||||||
|
[[IgnoredVulns]]
|
||||||
|
id = "RUSTSEC-2025-0080"
|
||||||
|
ignoreUntil = 2026-10-15
|
||||||
|
reason = "Maintenance-status advisory in Servo's pinned Unicode stack; migrate with the next Servo Unicode refresh."
|
||||||
|
|
||||||
|
[[IgnoredVulns]]
|
||||||
|
id = "RUSTSEC-2025-0100"
|
||||||
|
ignoreUntil = 2026-10-15
|
||||||
|
reason = "Maintenance-status advisory in Servo's pinned Unicode stack; migrate with the next Servo Unicode refresh."
|
||||||
|
|
||||||
|
[[IgnoredVulns]]
|
||||||
|
id = "RUSTSEC-2025-0098"
|
||||||
|
ignoreUntil = 2026-10-15
|
||||||
|
reason = "Maintenance-status advisory in Servo's pinned Unicode stack; migrate with the next Servo Unicode refresh."
|
||||||
Executable
+40
@@ -0,0 +1,40 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
repo_root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
||||||
|
cd "${repo_root}"
|
||||||
|
|
||||||
|
rsa_count="$(
|
||||||
|
awk '$0 == "name = \"rsa\"" { count += 1 } END { print count + 0 }' Cargo.lock
|
||||||
|
)"
|
||||||
|
|
||||||
|
if [[ "${rsa_count}" -ne 1 ]]; then
|
||||||
|
echo "RSA advisory exception requires exactly one locked RSA package" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
rsa_tree="$(
|
||||||
|
cargo tree --locked -p ely_servo_host \
|
||||||
|
--features servo-engine,hardware-render \
|
||||||
|
-e features \
|
||||||
|
-i rsa@0.10.0-rc.18
|
||||||
|
)"
|
||||||
|
|
||||||
|
if [[ "${rsa_tree%%$'\n'*}" != "rsa v0.10.0-rc.18 (${repo_root}/third_party/rsa)" ]]; then
|
||||||
|
echo "RSA advisory exception requires the vendored 0.10.0-rc.18 package" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ "${rsa_tree}" != *'rsa feature "private-key-operations-disabled"'* ]]; then
|
||||||
|
echo "RSA advisory exception requires private-key-operations-disabled" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
quick_xml_tree="$(
|
||||||
|
cargo tree --workspace --all-features --target all --locked -i quick-xml@0.30.0 2>/dev/null
|
||||||
|
)"
|
||||||
|
|
||||||
|
if [[ -n "${quick_xml_tree}" ]]; then
|
||||||
|
echo "quick-xml 0.30.0 advisory exception requires a lock-only dependency" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
Reference in New Issue
Block a user