Skip to content
This repository was archived by the owner on Sep 29, 2026. It is now read-only.
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 25 additions & 4 deletions .github/workflows/deny.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,16 @@ on:
default: "--all-features"
required: false
type: "string"
runner:
description: "Runner used for cargo deny"
default: "ubuntu-latest"
required: false
type: "string"
timeout-minutes:
description: "Timeout for the cargo deny job"
default: 30
required: false
type: "number"

permissions:
contents: read
Expand All @@ -23,7 +33,8 @@ env:
jobs:
cargo-deny:
name: cargo deny check
runs-on: ubuntu-latest
runs-on: ${{ inputs.runner }}
timeout-minutes: ${{ inputs.timeout-minutes }}
permissions:
contents: read
id-token: write
Expand All @@ -37,7 +48,17 @@ jobs:
- uses: tempoxyz/gh-actions/vendor/dtolnay/rust-toolchain@bce53819ffa60fcdf8f0f349686d807e5a66a71b # 2026-09-21T21-56-41Z-bce53819
with:
toolchain: ${{ inputs.rust-toolchain }}
- uses: tempoxyz/gh-actions/vendor/EmbarkStudios/cargo-deny-action@bce53819ffa60fcdf8f0f349686d807e5a66a71b # 2026-09-21T21-56-41Z-bce53819
- name: Install cargo-deny
uses: tempoxyz/gh-actions/vendor/taiki-e/install-action@bce53819ffa60fcdf8f0f349686d807e5a66a71b # 2026-09-21T21-56-41Z-bce53819
with:
command: check all
arguments: ${{ inputs.deny-flags }}
tool: cargo-deny@0.20.2
checksum: true
fallback: none
# Keep dependency downloads on the host configured by Secure Runner.
- name: Check dependencies
shell: bash
env:
DENY_FLAGS: ${{ inputs.deny-flags }}
run: |
read -r -a deny_flags <<< "$DENY_FLAGS"
cargo deny "${deny_flags[@]}" check all
12 changes: 12 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,15 @@
# tempoxyz/ci

Common GHA CI workflows.

Use `.github/workflows/deny.yml` for Cargo dependency checks. It configures
Secure Runner, installs a pinned, checksum-verified cargo-deny binary, and runs
the checks on the protected host. Callers must grant `contents: read` and
`id-token: write` to the reusable-workflow job.

The `rust-toolchain` input defaults to `nightly`. The `deny-flags` input defaults
to `--all-features` and accepts whitespace-separated cargo-deny flags (for
example, `--all-features --locked`). Set these inputs on the reusable call
instead of duplicating the installation and check steps in each repository.
Wrappers can also forward `runner` (default `ubuntu-latest`) and
`timeout-minutes` (default `30`) to preserve their existing job configuration.
Loading