Skip to content

CI Gedoens#2186

Draft
nichtsfrei wants to merge 11 commits intomainfrom
audits-destroy-the-vibe
Draft

CI Gedoens#2186
nichtsfrei wants to merge 11 commits intomainfrom
audits-destroy-the-vibe

Conversation

@nichtsfrei
Copy link
Copy Markdown
Member

What:

Why:

How:

Checklist:

  • Tests
  • PR merge commit message adjusted

@github-actions
Copy link
Copy Markdown

github-actions bot commented Apr 7, 2026

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ❌ 1 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses.
See the Details below.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA a52034a.
Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

License Issues

rust/Cargo.lock

PackageVersionLicenseIssue Type
openssl-src300.6.0+3.6.2LicenseRef-bad-mitapache-2.0Incompatible License
Allowed Licenses: 0BSD, AGPL-3.0-or-later, Apache-2.0, BlueOak-1.0.0, BSD-2-Clause, BSD-3-Clause-Clear, BSD-3-Clause, BSL-1.0, bzip2-1.0.6, CAL-1.0, CC-BY-3.0, CC-BY-4.0, CC-BY-SA-4.0, CC0-1.0, EPL-2.0, GPL-1.0-or-later, GPL-2.0-only, GPL-2.0-or-later, GPL-2.0, GPL-3.0-only, GPL-3.0-or-later, GPL-3.0, ISC, LGPL-2.0-only, LGPL-2.0-or-later, LGPL-2.1-only, LGPL-2.1-or-later, LGPL-2.1, LGPL-3.0-only, LGPL-3.0, LGPL-3.0-or-later, MIT, MIT-CMU, MPL-1.1, MPL-2.0, OFL-1.1, PSF-2.0, Python-2.0, Python-2.0.1, Unicode-3.0, Unicode-DFS-2016, Unlicense, Zlib, ZPL-2.1

OpenSSF Scorecard

PackageVersionScoreDetails
cargo/cc 1.2.60 🟢 5.6
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 8Found 14/17 approved changesets -- score normalized to 8
Packaging⚠️ -1packaging workflow not detected
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
cargo/hashbrown 0.17.0 🟢 5.6
Details
CheckScoreReason
Code-Review🟢 8Found 8/10 approved changesets -- score normalized to 8
Maintained🟢 1030 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
Security-Policy🟢 10security policy file detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
cargo/indexmap 2.14.0 UnknownUnknown
cargo/libredox 0.1.16 UnknownUnknown
cargo/openssl-src 300.6.0+3.6.2 🟢 4.1
Details
CheckScoreReason
Code-Review🟢 7Found 22/30 approved changesets -- score normalized to 7
Maintained⚠️ 23 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 2
Binary-Artifacts🟢 10no binaries found in the repo
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
cargo/redox_syscall 0.7.4 UnknownUnknown
cargo/rustls-webpki 0.103.11 UnknownUnknown
cargo/tokio 1.51.1 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 17 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 10all changesets reviewed
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy🟢 10security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
License🟢 10license file detected
Fuzzing🟢 10project is fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
cargo/toml_edit 0.25.11+spec-1.1.0 🟢 7.3
Details
CheckScoreReason
Code-Review🟢 3Found 6/17 approved changesets -- score normalized to 3
Maintained🟢 1030 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Security-Policy⚠️ 0security policy file not detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Fuzzing🟢 10project is fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST🟢 10SAST tool is run on all commits

Scanned Files

  • .github/workflows/functional.yaml
  • rust/Cargo.lock
  • rust/crates/smoketest/Cargo.toml

@nichtsfrei nichtsfrei force-pushed the audits-destroy-the-vibe branch from 2f5b0f8 to 9c0a454 Compare April 7, 2026 08:03
@nichtsfrei nichtsfrei changed the title Audits destroy the vibe CI Gedoens Apr 7, 2026
@nichtsfrei nichtsfrei force-pushed the audits-destroy-the-vibe branch 10 times, most recently from d86d098 to b8c514d Compare April 8, 2026 09:38
@github-actions github-actions bot added the minor_release creates a minor release label Apr 10, 2026
@nichtsfrei nichtsfrei force-pushed the audits-destroy-the-vibe branch from bae28fe to 6ac7eb7 Compare April 10, 2026 08:23
@github-actions github-actions bot added minor_release creates a minor release and removed minor_release creates a minor release labels Apr 10, 2026
@nichtsfrei nichtsfrei force-pushed the audits-destroy-the-vibe branch from 6ac7eb7 to 7e9cee3 Compare April 10, 2026 08:43
@github-actions github-actions bot added minor_release creates a minor release and removed minor_release creates a minor release labels Apr 10, 2026
@nichtsfrei nichtsfrei force-pushed the audits-destroy-the-vibe branch from 7e9cee3 to d8feff1 Compare April 10, 2026 08:47
@github-actions github-actions bot added minor_release creates a minor release and removed minor_release creates a minor release labels Apr 10, 2026
@nichtsfrei nichtsfrei force-pushed the audits-destroy-the-vibe branch from d8feff1 to 77fef1b Compare April 10, 2026 09:25
@github-actions github-actions bot added minor_release creates a minor release and removed minor_release creates a minor release labels Apr 10, 2026
@nichtsfrei nichtsfrei force-pushed the audits-destroy-the-vibe branch from 77fef1b to 1c73fb5 Compare April 10, 2026 11:46
@github-actions github-actions bot added minor_release creates a minor release and removed minor_release creates a minor release labels Apr 10, 2026
@nichtsfrei nichtsfrei force-pushed the audits-destroy-the-vibe branch from 1c73fb5 to ffd5ad3 Compare April 10, 2026 12:21
@github-actions github-actions bot added minor_release creates a minor release and removed minor_release creates a minor release labels Apr 13, 2026
@nichtsfrei nichtsfrei force-pushed the audits-destroy-the-vibe branch from 4f81740 to 60bc8f0 Compare April 13, 2026 08:18
@github-actions github-actions bot added minor_release creates a minor release and removed minor_release creates a minor release labels Apr 13, 2026
@nichtsfrei nichtsfrei force-pushed the audits-destroy-the-vibe branch from 60bc8f0 to 84b693b Compare April 13, 2026 08:38
@github-actions github-actions bot added minor_release creates a minor release and removed minor_release creates a minor release labels Apr 13, 2026
@nichtsfrei nichtsfrei force-pushed the audits-destroy-the-vibe branch from 84b693b to cbb84c0 Compare April 13, 2026 09:07
@github-actions github-actions bot added minor_release creates a minor release and removed minor_release creates a minor release labels Apr 13, 2026
@nichtsfrei nichtsfrei force-pushed the audits-destroy-the-vibe branch from cbb84c0 to 39830e5 Compare April 13, 2026 09:27
@github-actions github-actions bot added minor_release creates a minor release and removed minor_release creates a minor release labels Apr 13, 2026
@nichtsfrei nichtsfrei force-pushed the audits-destroy-the-vibe branch from 39830e5 to ed04839 Compare April 13, 2026 10:00
@github-actions github-actions bot added minor_release creates a minor release and removed minor_release creates a minor release labels Apr 13, 2026
@nichtsfrei nichtsfrei force-pushed the audits-destroy-the-vibe branch from 00192a8 to a52034a Compare April 13, 2026 12:01
@github-actions github-actions bot removed the minor_release creates a minor release label Apr 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

minor_release creates a minor release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant