fix: do not fail when Cargo.lock is not found#39
Open
flavio wants to merge 1 commit intorustsec:masterfrom
Open
fix: do not fail when Cargo.lock is not found#39flavio wants to merge 1 commit intorustsec:masterfrom
flavio wants to merge 1 commit intorustsec:masterfrom
Conversation
Fix a regression introduced by `working-directory` settings, introduced by commit b7dc4eb. The commit started to invoke `cargo-audit` with the `--file <working-dir>/Cargo.lock` flag. However not all the Rust projects have `Cargo.lock` files committed; take libraries as an example. This commit changes the `working-directory` default value to be an empty string. In this way the `--file` flag can be added only when the user actually provides this parameter. Finally, the code has been changed to build the final path to the `Cargo.lock` file in a more robust way. The prior code assumed the action would be run on a unix system. It would have failed on a Windows machine. Signed-off-by: Flavio Castelli <fcastelli@suse.com>
Author
|
@tarcieri can you help finding someone who could review this PR? thanks! |
|
Please merge this @tarcieri |
becomingwisest
added a commit
to becomingwisest/rtic
that referenced
this pull request
Sep 12, 2025
Allow on demand action checks use latest actions/checkout --- rtic-rs#1080 switched to using rustsec/audit-check but didn't setup the Cargo.lock file. This action has been failing for three months. https://github.com/rtic-rs/rtic/actions/workflows/audit.yaml --- rustsec/audit-check#39 describes how a missing Cargo.lock will be missing in library crates.
becomingwisest
added a commit
to becomingwisest/rtic
that referenced
this pull request
Sep 12, 2025
Allow on demand action checks use latest actions/checkout --- rtic-rs#1080 switched to using rustsec/audit-check but didn't setup the Cargo.lock file. This action has been failing for three months. https://github.com/rtic-rs/rtic/actions/workflows/audit.yaml --- rustsec/audit-check#39 describes how a missing Cargo.lock will be missing in library crates.
AfoHT
pushed a commit
to becomingwisest/rtic
that referenced
this pull request
Sep 17, 2025
Allow on demand action checks use latest actions/checkout --- rtic-rs#1080 switched to using rustsec/audit-check but didn't setup the Cargo.lock file. This action has been failing for three months. https://github.com/rtic-rs/rtic/actions/workflows/audit.yaml --- rustsec/audit-check#39 describes how a missing Cargo.lock will be missing in library crates.
github-merge-queue bot
pushed a commit
to rtic-rs/rtic
that referenced
this pull request
Sep 17, 2025
Allow on demand action checks use latest actions/checkout --- #1080 switched to using rustsec/audit-check but didn't setup the Cargo.lock file. This action has been failing for three months. https://github.com/rtic-rs/rtic/actions/workflows/audit.yaml --- rustsec/audit-check#39 describes how a missing Cargo.lock will be missing in library crates.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fix a regression introduced by
working-directorysettings, introduced by commit b7dc4eb.The commit started to invoke
cargo-auditwith the--file <working-dir>/Cargo.lockflag.However not all the Rust projects have
Cargo.lockfiles committed; take libraries as an example.This commit changes the
working-directorydefault value to be an empty string. In this way the--fileflag can be added only when the user actually provides this parameter.Finally, the code has been changed to build the final path to the
Cargo.lockfile in a more robust way. The prior code assumed the action would be run on a unix system. It would have failed on a Windows machine.