Repository navigation
Daily Security Audit #1
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| --- | |
| name: Daily Security Audit | |
| on: | |
| schedule: | |
| # Run every day at 04:15 UTC: https://crontab.guru/#15_4_*_*_* | |
| - cron: '15 4 * * *' | |
| workflow_dispatch: | |
| # rustsec/audit-check reports findings by opening a GitHub issue, and records a | |
| # check run. With contents:read alone it cannot do either, so a new advisory | |
| # would fail silently and the job's green status would mean nothing. | |
| permissions: | |
| contents: read | |
| issues: write | |
| checks: write | |
| jobs: | |
| audit: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 | |
| with: | |
| persist-credentials: false | |
| token: ${{ secrets.GITHUB_TOKEN }} | |
| - uses: rustsec/audit-check@69366f33c96575abad1ee0dba8212993eecbe998 # v2.0.0 | |
| with: | |
| token: ${{ secrets.GITHUB_TOKEN }} |