Skip to content

feat(integrations): committed Hermes plugin package + drift guard #1892

feat(integrations): committed Hermes plugin package + drift guard

feat(integrations): committed Hermes plugin package + drift guard #1892

Workflow file for this run

name: Security
on:
push:
branches: [develop, main]
pull_request:
branches: [develop, main]
schedule:
# Run daily at 06:00 UTC
- cron: "0 6 * * *"
workflow_dispatch:
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
jobs:
cargo-audit:
name: Cargo Audit
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
- name: Install cargo-audit
run: cargo install cargo-audit
- name: Run cargo audit
# Ignored advisories (with justification):
# RUSTSEC-2024-0436: paste unmaintained — informational, no vulnerability
# RUSTSEC-2026-0185: quinn-proto — comes transitively via reqwest/hyper,
# not used in server-facing code paths. Update when reqwest bumps quinn.
# RUSTSEC-2026-0202: cxx unsound — transitive dep, waiting for upstream consumers to bump
# RUSTSEC-2026-0190: anyhow unsound — transitive dep, waiting for upstream consumers to bump
run: cargo audit --ignore RUSTSEC-2024-0436 --ignore RUSTSEC-2026-0185 --ignore RUSTSEC-2026-0202 --ignore RUSTSEC-2026-0190
trivy:
name: Trivy FS Scan
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@v0.36.0
with:
scan-type: "fs"
scan-ref: "."
format: "table"
exit-code: "1"
severity: "CRITICAL,HIGH"
ignore-unfixed: true