Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add workflow for dependabot and cargo vet #537

Merged
merged 2 commits into from
Oct 26, 2023
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
60 changes: 60 additions & 0 deletions .github/workflows/dependabot-cargo-vet.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
# Runs cargo vet for Dependabot PRs
name: Dependabot update cargo vet
on:
push:
branches:
- "dependabot/cargo/**"

jobs:
vet:
runs-on: ubuntu-latest

permissions:
contents: write

env:
CARGO_VET_VERSION: 0.8.0

steps:
- uses: actions/checkout@v4

- uses: actions/cache@v3
with:
path: ${{ runner.tool_cache }}/cargo-vet
key: cargo-vet-bin-${{ env.CARGO_VET_VERSION }}

- name: Add the tool cache directory to the search path
run: echo "${{ runner.tool_cache }}/cargo-vet/bin" >> $GITHUB_PATH

- name: Ensure that the tool cache is populated with the cargo-vet binary
run: cargo install --root ${{ runner.tool_cache }}/cargo-vet --version ${{ env.CARGO_VET_VERSION }} cargo-vet

- run: cargo vet
continue-on-error: true

# These all ask for input on the terminal to select the trusted criteria but take the default of `safe-to-deploy`.

- run: cargo vet trust --all BurntSushi
continue-on-error: true

- run: cargo vet trust --all sunfishcode
continue-on-error: true

- run: cargo vet trust --all dtolnay
continue-on-error: true

- run: cargo vet trust --all cuviper
continue-on-error: true

- run: cargo vet trust --all Amanieu
continue-on-error: true

- name: commit and push
shell: bash
run: |
if ! git diff --exit-code; then
git config --global user.name 'github-actions[bot]'
git config --global user.email 'github-actions[bot]@users.noreply.github.com'
git commit -am "[dependabot skip] Regenerate cargo vet"
git push
fi