feat(simulation): add cargo audit to CI/review pipeline (#637)
Add `make audit` target running `cargo audit` with an advisory ignore for RUSTSEC-2025-0141 (bincode, tracked by #636). Wire audit into `make pre-pr` and `make pre-pr-server`. Add conditional cargo audit to the pre-commit hook (triggers only when Cargo.toml/Cargo.lock are staged). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -23,6 +23,19 @@ run_check() {
|
||||
run_check "tooling/check-fact-ids" "fact_id validation"
|
||||
run_check "tooling/check-decision-ids" "decision ID duplication"
|
||||
|
||||
# Run cargo audit only when Cargo.toml or Cargo.lock changed
|
||||
if git diff --cached --name-only | grep -qE '(Cargo\.toml|Cargo\.lock)$'; then
|
||||
echo "pre-commit: Cargo dependency change detected — running cargo audit..."
|
||||
if command -v cargo-audit >/dev/null 2>&1 || cargo audit --version >/dev/null 2>&1; then
|
||||
if ! (cd "$REPO_ROOT/server" && cargo audit); then
|
||||
ERRORS=$((ERRORS + 1))
|
||||
fi
|
||||
else
|
||||
echo "pre-commit: WARNING — cargo-audit not installed, skipping advisory check"
|
||||
echo " Install with: cargo install cargo-audit"
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ "$ERRORS" -gt 0 ]; then
|
||||
echo ""
|
||||
echo "pre-commit: $ERRORS check(s) failed. Commit aborted."
|
||||
|
||||
Reference in New Issue
Block a user