Skip to content

refactor(tests): one shared as_tenant helper; cut unused _original_te… #1865

refactor(tests): one shared as_tenant helper; cut unused _original_te…

refactor(tests): one shared as_tenant helper; cut unused _original_te… #1865

Workflow file for this run

name: Security Fast
on:
push:
branches: [ main, develop ]
pull_request:
branches: [ main, develop ]
permissions:
contents: read
pull-requests: read
checks: write # Required for rustsec/audit-check to create check runs
security-events: write
env:
CARGO_TERM_COLOR: always
RUST_BACKTRACE: 1
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
# Fast security checks - parallel execution. Hosted runners start cold, so
# each tool's first `cargo install` compiles from source; rust-cache keeps
# ~/.cargo/bin across runs so later runs skip it (cargo-machete installs in
# under a minute cold, so it goes without). Timeouts cover the cold path.
cargo-audit:
name: Vulnerability Scan
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
# audit-check runs `cargo install cargo-audit` when the binary is absent;
# caching ~/.cargo/bin makes that a one-off.
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
- uses: rustsec/audit-check@69366f33c96575abad1ee0dba8212993eecbe998 # v2
with:
token: ${{ secrets.GITHUB_TOKEN }}
# quick-xml DoS advisories: dev-only via pprof->inferno, no upgrade path.
# Keep in sync with deny.toml [advisories].ignore.
ignore: RUSTSEC-2026-0194,RUSTSEC-2026-0195
cargo-deny:
name: License & Supply Chain
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
- name: Install cargo-deny
run: cargo install --locked cargo-deny
- name: Run cargo-deny
run: cargo deny --all-features check
clippy-security:
name: Security Lints
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
# Caches target/ and the registry for the clippy build (nothing installed here).
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
- name: Run Clippy security lints
run: |
cd rust
cargo clippy --no-default-features --features compression,checksum,messagepack,encryption \
-- -D warnings -W clippy::cargo -W clippy::pedantic
cargo-machete:
name: Unused Dependencies
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
- name: Install cargo-machete
run: cargo install --locked cargo-machete
- name: Check for unused dependencies
run: |
cd rust
cargo machete
pip-audit:
name: Python Dependency CVEs
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
- uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: "0.12.19" # pinned: uv runs as step 1 of every job; a floating release is code exec
# `uv sync` builds the Rust extension via maturin — cache its dependencies.
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
- name: Install dependencies
run: |
uv sync --group dev
- name: Run pip-audit
run: |
# No suppressions: every prior CVE is resolved at source on the py3.10+
# resolution. Vulnerable dev-only transitives are floored via
# [tool.uv] constraint-dependencies; pygments/pyarrow advisories cleared
# by their py3.10+ fix versions. Keep this list IDENTICAL to ci.yml's
# post-merge pip-audit so the two cannot drift.
uv run pip-audit --desc --format json --output pip-audit-report.json
- name: Upload report
if: always()
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7
with:
name: pip-audit-report
path: pip-audit-report.json
# Summary job - fail if any check fails
security-fast-success:
name: Security Fast Success
runs-on: ubuntu-latest
needs: [cargo-audit, cargo-deny, clippy-security, cargo-machete, pip-audit]
if: always()
steps:
- name: Check all security checks passed
run: |
if [[ "${{ needs.cargo-audit.result }}" != "success" ]] || \
[[ "${{ needs.cargo-deny.result }}" != "success" ]] || \
[[ "${{ needs.clippy-security.result }}" != "success" ]] || \
[[ "${{ needs.cargo-machete.result }}" != "success" ]] || \
[[ "${{ needs.pip-audit.result }}" != "success" ]]; then
echo "❌ One or more security checks failed"
exit 1
fi
echo "✅ All fast security checks passed"