Skip to content

feat(security): release-triggered cargo vulnerability scan#1292

Open
Cr0wTom wants to merge 3 commits into
mainfrom
security/cargo-vuln-scan
Open

feat(security): release-triggered cargo vulnerability scan#1292
Cr0wTom wants to merge 3 commits into
mainfrom
security/cargo-vuln-scan

Conversation

@Cr0wTom

@Cr0wTom Cr0wTom commented Jun 26, 2026

Copy link
Copy Markdown
Collaborator

What

Adds .github/workflows/vuln-scan.yaml — on release: published, calls the
shared orb-internal/cargo-vuln-scan reusable workflow with
platform-tag: orb-software.

Result

grype SARIF is uploaded to this repo's Security → Code scanning tab; a
prioritized bump queue + summary table are produced from the released version's
Cargo.lock (honoring this repo's deny.toml).

@Cr0wTom Cr0wTom requested a review from vmenge June 26, 2026 14:44
@Cr0wTom Cr0wTom requested a review from a team as a code owner June 26, 2026 14:44
@Cr0wTom Cr0wTom enabled auto-merge (squash) June 26, 2026 16:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants