Repository navigation
refactor(tests): one shared as_tenant helper; cut unused _original_te… #1865
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Security Fast | |
| on: | |
| push: | |
| branches: [ main, develop ] | |
| pull_request: | |
| branches: [ main, develop ] | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| checks: write # Required for rustsec/audit-check to create check runs | |
| security-events: write | |
| env: | |
| CARGO_TERM_COLOR: always | |
| RUST_BACKTRACE: 1 | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| # Fast security checks - parallel execution. Hosted runners start cold, so | |
| # each tool's first `cargo install` compiles from source; rust-cache keeps | |
| # ~/.cargo/bin across runs so later runs skip it (cargo-machete installs in | |
| # under a minute cold, so it goes without). Timeouts cover the cold path. | |
| cargo-audit: | |
| name: Vulnerability Scan | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 | |
| # audit-check runs `cargo install cargo-audit` when the binary is absent; | |
| # caching ~/.cargo/bin makes that a one-off. | |
| - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | |
| - uses: rustsec/audit-check@69366f33c96575abad1ee0dba8212993eecbe998 # v2 | |
| with: | |
| token: ${{ secrets.GITHUB_TOKEN }} | |
| # quick-xml DoS advisories: dev-only via pprof->inferno, no upgrade path. | |
| # Keep in sync with deny.toml [advisories].ignore. | |
| ignore: RUSTSEC-2026-0194,RUSTSEC-2026-0195 | |
| cargo-deny: | |
| name: License & Supply Chain | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 | |
| - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | |
| - name: Install cargo-deny | |
| run: cargo install --locked cargo-deny | |
| - name: Run cargo-deny | |
| run: cargo deny --all-features check | |
| clippy-security: | |
| name: Security Lints | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 | |
| # Caches target/ and the registry for the clippy build (nothing installed here). | |
| - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | |
| - name: Run Clippy security lints | |
| run: | | |
| cd rust | |
| cargo clippy --no-default-features --features compression,checksum,messagepack,encryption \ | |
| -- -D warnings -W clippy::cargo -W clippy::pedantic | |
| cargo-machete: | |
| name: Unused Dependencies | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 5 | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 | |
| - name: Install cargo-machete | |
| run: cargo install --locked cargo-machete | |
| - name: Check for unused dependencies | |
| run: | | |
| cd rust | |
| cargo machete | |
| pip-audit: | |
| name: Python Dependency CVEs | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 | |
| - uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 | |
| with: | |
| version: "0.12.19" # pinned: uv runs as step 1 of every job; a floating release is code exec | |
| # `uv sync` builds the Rust extension via maturin — cache its dependencies. | |
| - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | |
| - name: Install dependencies | |
| run: | | |
| uv sync --group dev | |
| - name: Run pip-audit | |
| run: | | |
| # No suppressions: every prior CVE is resolved at source on the py3.10+ | |
| # resolution. Vulnerable dev-only transitives are floored via | |
| # [tool.uv] constraint-dependencies; pygments/pyarrow advisories cleared | |
| # by their py3.10+ fix versions. Keep this list IDENTICAL to ci.yml's | |
| # post-merge pip-audit so the two cannot drift. | |
| uv run pip-audit --desc --format json --output pip-audit-report.json | |
| - name: Upload report | |
| if: always() | |
| uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7 | |
| with: | |
| name: pip-audit-report | |
| path: pip-audit-report.json | |
| # Summary job - fail if any check fails | |
| security-fast-success: | |
| name: Security Fast Success | |
| runs-on: ubuntu-latest | |
| needs: [cargo-audit, cargo-deny, clippy-security, cargo-machete, pip-audit] | |
| if: always() | |
| steps: | |
| - name: Check all security checks passed | |
| run: | | |
| if [[ "${{ needs.cargo-audit.result }}" != "success" ]] || \ | |
| [[ "${{ needs.cargo-deny.result }}" != "success" ]] || \ | |
| [[ "${{ needs.clippy-security.result }}" != "success" ]] || \ | |
| [[ "${{ needs.cargo-machete.result }}" != "success" ]] || \ | |
| [[ "${{ needs.pip-audit.result }}" != "success" ]]; then | |
| echo "❌ One or more security checks failed" | |
| exit 1 | |
| fi | |
| echo "✅ All fast security checks passed" |