Skip to content

feat(ferrox-cp): M2 crypto core — RSA keygen, AES-256-GCM, JWT signing #39

feat(ferrox-cp): M2 crypto core — RSA keygen, AES-256-GCM, JWT signing

feat(ferrox-cp): M2 crypto core — RSA keygen, AES-256-GCM, JWT signing #39

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
env:
CARGO_TERM_COLOR: always
RUST_BACKTRACE: 1
jobs:
# ── Format ───────────────────────────────────────────────────────────────────
fmt:
name: Format
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@stable
with:
components: rustfmt
- run: cargo fmt --all --check
# ── Lint ─────────────────────────────────────────────────────────────────────
clippy:
name: Clippy
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@stable
with:
components: clippy
- uses: Swatinem/rust-cache@v2
- name: Install protobuf compiler
run: sudo apt-get update && sudo apt-get install -y protobuf-compiler
- run: cargo clippy --workspace -- -D warnings
# ── Test ─────────────────────────────────────────────────────────────────────
test:
name: Test
runs-on: ubuntu-latest
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_USER: postgres
POSTGRES_PASSWORD: testpass
POSTGRES_DB: postgres
ports:
- 5432:5432
options: >-
--health-cmd "pg_isready -U postgres"
--health-interval 5s
--health-timeout 5s
--health-retries 10
env:
DATABASE_URL: postgres://postgres:testpass@localhost:5432/postgres
steps:
- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
- name: Install protobuf compiler
run: sudo apt-get update && sudo apt-get install -y protobuf-compiler
- run: cargo test --workspace -- --test-threads=1
# ── Build release ─────────────────────────────────────────────────────────────
build:
name: Build (release)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
- name: Install protobuf compiler
run: sudo apt-get update && sudo apt-get install -y protobuf-compiler
- run: cargo build --release --workspace
# ── Security audit ────────────────────────────────────────────────────────────
audit:
name: Security audit
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: rustsec/audit-check@v1
with:
token: ${{ secrets.GITHUB_TOKEN }}
# RUSTSEC-2023-0071: timing side-channel in `rsa` crate (Marvin Attack).
# Pulled in transitively via sqlx → sqlx-mysql → rsa. We do not use MySQL
# or any RSA operations through sqlx-mysql; no patch is available upstream.
ignore: RUSTSEC-2023-0071
# ── Config schema validation ──────────────────────────────────────────────────
validate-config:
name: Validate config schema
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- run: pip install check-jsonschema
- run: check-jsonschema --schemafile ferrox/config.schema.json ferrox/config/*.yaml