Skip to content
This repository was archived by the owner on Sep 29, 2026. It is now read-only.

fix(ci): run shared deny on the protected host - #24

Closed
decofe wants to merge 2 commits into
mainfrom
centaur/secure-shared-deny-20260922
Closed

decofe wants to merge 2 commits into
mainfrom
centaur/secure-shared-deny-20260922

Conversation

@decofe

@decofe decofe commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

Run cargo-deny on the host configured by Secure Runner so callers can keep using tempoxyz/ci/.github/workflows/deny.yml without copying the setup into each repository. Replace the Docker action with a pinned, checksum-verified cargo-deny 0.20.2 installation and retain the existing toolchain and flags inputs. Optional runner and timeout inputs allow other shared workflows to delegate their deny job here without losing configuration; the defaults are ubuntu-latest and 30 minutes.

The workflow passes actionlint and the flag forwarding was checked for the default, empty, and --locked inputs. The restored caller in alloy-rs/chains#331 has passed its deny job.

Prompted by: @DaniPopes

Keep the reusable deny interface while running the audit on the host configured by Secure Runner.

Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
Allow reusable lint wrappers to share the deny implementation without losing runner or timeout configuration.

Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants