Add RustSec audit job to CI - #54
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Install a pinned cargo-audit version before running the audit command.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Adds a RustSec dependency-audit job to CI for both repository lockfiles, with SARIF uploads to GitHub code scanning.
Changes:
- Adds a matrix-based audit job.
- Rewrites and uploads SARIF reports.
- Requires installing
cargo-auditbefore invocation; currently both legs fail.
| File | Description |
|---|---|
.github/workflows/basic.yml |
Adds the RustSec audit matrix job and SARIF reporting. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
75d3423 to
cf98949
Compare
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
fe9d21e to
12530bd
Compare
szymon-zadworny
left a comment
There was a problem hiding this comment.
The /sycl/sycl-rs-sys/Cargo.lock file should be removed as it's unnecessary.
There was a problem hiding this comment.
This file is a leftover from the initial demo and can be safely removed.
76c89d1 to
3d32fc4
Compare

Add RustSec audit job to CI