chore: enable cargo-audit in CI #352
Merged
+398
−301
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Pull Request Title
Enable
cargo auditin CIDescription
Run
cargo auditas part of the suite of tests required to merge a PR. This is a tool which detects when the project depends on crates with reported vulnerabilities. The typical fix is to update those vulnerable crates (manually or by runningcargo update)Related Issue(s)
Contributes to #260
How was this tested?
This very PR is green (and I checked, the audit was run
Checklist
Impact / Side effects
This can potentially disrupt development, by preventing merges if a vulnerability is reported in a crate. If that happens, we need to fix the vulnerability immediately, or add it to the ignore list. I've disabled "informational" warnings (about e.g. unmaintained crates) to make sure this only happens for legit issues.
Reviewer notes / Areas to focus