Skip to content

Dependabot + cargo-audit in CI#166

Open
heymide wants to merge 1 commit into
Dgetsylver:mainfrom
heymide:dependabot
Open

Dependabot + cargo-audit in CI#166
heymide wants to merge 1 commit into
Dgetsylver:mainfrom
heymide:dependabot

Conversation

@heymide
Copy link
Copy Markdown

@heymide heymide commented May 29, 2026

Close: #85

Summary

Both files are committed to the repo:

dependabot.yml
— schema v2 with 4 ecosystem entries, all on a weekly Monday schedule:

cargo at /
npm at frontend/, alerts/, scripts/
rust-ci.yml
— new Rust CI workflow with:

Triggers on push and pull_request to main
permissions: contents: read (works for Dependabot PRs)
Stable Rust toolchain via dtolnay/rust-toolchain@stable
cargo-audit install with actions/cache@v4 keyed on CARGO_AUDIT_VERSION: "0.21.0" — skips reinstall on cache hit
cargo audit with continue-on-error: true — surfaces advisories as a visible failure while letting build/test still run; the overall workflow still fails and blocks PR merge
cargo build and cargo test as final steps

Related Issue

Closes #85

Checks

  • I read the contribution guide.
  • I kept this pull request scoped to the linked issue.
  • I ran the relevant local checks or explained why they were skipped.
  • For Drips wave issues, I claimed the issue before opening this pull request.

Notes for Reviewers

@drips-wave
Copy link
Copy Markdown

drips-wave Bot commented May 29, 2026

@heymide Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@heymide
Copy link
Copy Markdown
Author

heymide commented May 29, 2026

Done, Close: #166

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

H1: Dependabot + cargo-audit in CI

2 participants