Harden dependency and supply-chain policy (#100)
Some checks failed
Native code generation / deterministic (push) Failing after 2m6s
Imaging and meshing gate / native (push) Failing after 2m48s
JPEG 2000 feature / linux (push) Successful in 2m43s
Release platform and feature matrix / audit (push) Successful in 35s
Native Rust workspace compile / compile (push) Failing after 57s
Skia feature / linux (push) Successful in 31m0s
Release platform and feature matrix / matrix (false, linux-stable-minimal, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (false, macos-stable-portable, x86_64-apple-darwin, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (false, windows-stable-portable, x86_64-pc-windows-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-msrv-portable, x86_64-unknown-linux-gnu, 1.96.0) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-stable-default, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-stable-features, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-stable-release-surface, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Dependency and supply-chain audit / audit (push) Has been cancelled

This commit is contained in:
2026-08-11 22:57:13 +00:00
parent 9779e50ce9
commit 9e3b532a7e
21 changed files with 2086 additions and 78 deletions

View File

@@ -1,4 +1,4 @@
use metacrate_ci_matrix::{audit, load, run, workspace_root};
use metacrate_ci_matrix::{audit, audit_dependencies, load, run, workspace_root};
use std::path::{Path, PathBuf};
fn main() {
@@ -32,7 +32,26 @@ fn execute() -> Result<(), Box<dyn std::error::Error>> {
run(&root, &matrix, &profile, &evidence)?;
println!("release CI profile {profile}: ok ({})", evidence.display());
}
_ => return Err("usage: ci-matrix audit | run PROFILE --evidence FILE".into()),
Some("dependency-audit") => {
let flag = arguments
.next()
.ok_or("dependency-audit requires --evidence FILE")?;
let evidence = arguments
.next()
.ok_or("dependency-audit requires --evidence FILE")?;
if flag != "--evidence" || arguments.next().is_some() {
return Err("usage: ci-matrix dependency-audit --evidence FILE".into());
}
let evidence = absolute_or_rooted(&root, &evidence);
audit_dependencies(&root, &evidence)?;
println!("dependency policy: ok ({})", evidence.display());
}
_ => {
return Err(
"usage: ci-matrix audit | run PROFILE --evidence FILE | dependency-audit --evidence FILE"
.into(),
);
}
}
Ok(())
}