feat(integrations): committed Hermes plugin package + drift guard #1892
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Security | |
| on: | |
| push: | |
| branches: [develop, main] | |
| pull_request: | |
| branches: [develop, main] | |
| schedule: | |
| # Run daily at 06:00 UTC | |
| - cron: "0 6 * * *" | |
| workflow_dispatch: | |
| env: | |
| FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true | |
| jobs: | |
| cargo-audit: | |
| name: Cargo Audit | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: dtolnay/rust-toolchain@stable | |
| - name: Install cargo-audit | |
| run: cargo install cargo-audit | |
| - name: Run cargo audit | |
| # Ignored advisories (with justification): | |
| # RUSTSEC-2024-0436: paste unmaintained — informational, no vulnerability | |
| # RUSTSEC-2026-0185: quinn-proto — comes transitively via reqwest/hyper, | |
| # not used in server-facing code paths. Update when reqwest bumps quinn. | |
| # RUSTSEC-2026-0202: cxx unsound — transitive dep, waiting for upstream consumers to bump | |
| # RUSTSEC-2026-0190: anyhow unsound — transitive dep, waiting for upstream consumers to bump | |
| run: cargo audit --ignore RUSTSEC-2024-0436 --ignore RUSTSEC-2026-0185 --ignore RUSTSEC-2026-0202 --ignore RUSTSEC-2026-0190 | |
| trivy: | |
| name: Trivy FS Scan | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Run Trivy vulnerability scanner | |
| uses: aquasecurity/trivy-action@v0.36.0 | |
| with: | |
| scan-type: "fs" | |
| scan-ref: "." | |
| format: "table" | |
| exit-code: "1" | |
| severity: "CRITICAL,HIGH" | |
| ignore-unfixed: true |