dependabot[bot]
bf05d075a1
Bump actions/checkout from 3 to 4 ( #3171 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 3 to 4.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v3...v4 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-11 22:05:04 -04:00
dependabot[bot]
33eab5632c
Bump actions/checkout from 2 to 3
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 2 to 3.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v2...v3 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
2023-01-15 15:29:42 -05:00
Dustin J. Mitchell
9c0bccd08a
rustsec org is now hosting audit-check
2022-08-11 01:14:37 -04:00
Dustin J. Mitchell
38ad3bc14b
spell audit-check repo correctly
2022-08-11 01:14:37 -04:00
Dustin J. Mitchell
4852b146a8
stop using forked audit action
2022-08-06 20:55:39 -04:00
Dustin J. Mitchell
bad3b3d700
use the (existing) .cargo/audit.toml to ignore some rust advisories
2022-08-06 20:55:39 -04:00
Dustin J. Mitchell
72a8be3340
Update .github/workflows/security.yml
...
Co-authored-by: Tomas Babej <tomas@tbabej.com>
2022-07-24 16:46:45 -04:00
Dustin J. Mitchell
56ea105e25
Ignore RUSTSEC-2020-0071
...
See discussion at
https://github.com/taskchampion/taskchampion/issues/304 . Note that
RUSTSEC-2020-0159 is the same bug as RUSTSEC-2020-0071.
2022-07-24 16:46:45 -04:00
Dustin J. Mitchell
3aa14b3efc
ignore RUSTSEC-2021-0124
...
This is a vulnerability in tokio, which is required by Actix-web. For
the moment, ignore it, and then decide whether to upgrade actix to suit,
or switch to a different (simpler) web server package.
2022-07-24 16:46:45 -04:00
Dustin J. Mitchell
977ab11af2
Revert "temporarily remove cargo audit check"
...
This reverts commit 892efd0b13
.
2022-07-24 16:46:45 -04:00
Dustin J. Mitchell
d422db32ea
temporarily remove cargo audit check
2022-06-12 18:07:44 -04:00
Dustin J. Mitchell
085da00b0c
add write-all permission to the audit
2022-05-28 08:33:20 -04:00
Dustin J. Mitchell
9f5994bfd1
Update GitHub actions to work in Taskwarrior
...
This moves the workspace Cargo.toml to the root of the repository, so
that the "actions-rs/cargo" action can find it.
2022-05-08 20:06:05 +00:00