-
-
Notifications
You must be signed in to change notification settings - Fork 3
supply chain
github-actions[bot] edited this page Oct 3, 2026
·
1 revision
The build uses few dependencies. Tools and actions are pinned. Every dependency change is reviewed.
- cargo-deny checks bans and sources on every PR (
security.yml). - Socket.dev reviews dependency changes for advisories, licenses and supply-chain risk. The config is
socket.yml. - Dependabot opens update PRs (
.github/dependabot.yml). - CI actions are pinned by full commit SHA.
- CI tools (actionlint, gitleaks, lizard) are pinned by version and SHA-256 hash.
- Run
cargo deny --manifest-path src-tauri/Cargo.toml check bans sources. - Install lint tools with
pip install --require-hashes -r scripts/requirements-lint.txt. - Give a reason for each new dependency in the PR.
- Socket policy lives in the Socket dashboard, not in the repo.
- cargo-deny does not check advisories or licenses. Socket does.
Generated from docs/wiki in the repository. Edit there, not here.