Skip to content

feat(security): add cargo-vet for supply chain tracking#54

Merged
chaliy merged 1 commit intomainfrom
claude/implement-cargo-vet-VfGYF
Feb 2, 2026
Merged

feat(security): add cargo-vet for supply chain tracking#54
chaliy merged 1 commit intomainfrom
claude/implement-cargo-vet-VfGYF

Conversation

@chaliy
Copy link
Contributor

@chaliy chaliy commented Feb 2, 2026

Summary

  • Initialize cargo-vet for supply chain security tracking
  • Add cargo-vet check to CI pipeline (runs after license check)
  • Add just vet, just vet-suggest, just vet-certify commands
  • Include vet in just pre-pr checks

Details

cargo-vet tracks third-party dependencies and ensures they are vetted before use. This PR sets up the initial configuration with exemptions for all existing dependencies (304 crates).

Over time, exemptions can be reduced by:

  1. Adding first-party audits to supply-chain/audits.toml
  2. Importing audits from trusted organizations (Mozilla, Google, etc.) via cargo vet import
  3. Trusting specific crate authors via cargo vet trust

New dependencies will fail CI until properly vetted, ensuring supply chain security.

Test plan

  • cargo vet passes locally (304 exempted)
  • CI passes with cargo-vet check

https://claude.ai/code/session_0191f8yvDXNvbNxP5JSEoWQu

- Initialize cargo-vet with exemptions for existing dependencies
- Add cargo-vet check to CI pipeline (after license check)
- Add vet, vet-suggest, vet-certify commands to justfile
- Include vet in pre-pr checks

Supply chain security is now enforced: all dependencies require either
an audit (in audits.toml), an import from trusted sources, or an explicit
exemption. New dependencies will fail CI until vetted.

https://claude.ai/code/session_0191f8yvDXNvbNxP5JSEoWQu
@chatgpt-codex-connector
Copy link

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@chaliy chaliy merged commit 082b3a5 into main Feb 2, 2026
7 checks passed
@chaliy chaliy deleted the claude/implement-cargo-vet-VfGYF branch February 2, 2026 05:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants