YAML choked on the leading backtick in the description value (line 2 column 14 — the `cargo-audit` inline-code span). Quoting the whole string makes it a scalar, not a tag/anchor. Surfaced by prod server logs after today's compose refresh.
2.9 KiB
2.9 KiB
name, description, when_to_use, tags
| name | description | when_to_use | tags | |||
|---|---|---|---|---|---|---|
| cargo-audit-workflow | `cargo-audit` (rustsec) — how to run it, triage findings, and integrate into the security template's mission flow. | You're on a security mission or investigating a RUSTSEC advisory in a Rust project. |
|
cargo-audit workflow
Anchored to cargo-audit 0.21+ (2026 line) reading the RustSec Advisory DB.
Basic usage
cargo install cargo-audit --locked
cargo audit # scans Cargo.lock, reports vulnerabilities
cargo audit fetch # update advisory DB
cargo audit --deny warnings # non-zero on any warning too (yanked crates, unmaintained)
CI runs: cargo audit --deny warnings --json — JSON output goes to the mission's mission_artifacts as a security_report.
Triage each finding
For every advisory the report surfaces:
-
Is the vulnerable path reachable from OUR code?
cargo tree -i <cratename>shows who depends on it.- Sometimes a vulnerable transitive dep is only exercised by a feature you don't enable — check the report's
affected_functions.
-
What versions fix it?
- The advisory lists
patched_versions. Trycargo update -p <crate> --precise <version>to hop to a patched minor without a semver-major bump. - If patched only in a newer major, plan the migration (may be a multi-INT effort).
- The advisory lists
-
Is there a
RUSTSECallowlist for a known-false-positive?[advisories.ignore]inaudit.toml— with a comment explaining WHY and a ticket link + expiry date.- Never ignore without expiry; reviewers should re-evaluate quarterly.
Common findings + fixes
RUSTSEC-YYYY-NNNNon a dev-dep: less urgent, but fix anyway — dev tools run in CI with elevated permissions.- Yanked crate — the version was pulled from crates.io. Update immediately;
cargo update -p <crate>picks the next non-yanked. - Unmaintained crate warning — no CVE yet, but the maintainer walked away. Long-term: replace. Short-term: pin and document.
Integration with the security mission template
The security-hardening mission runs cargo audit --json in the security_scan phase. Each finding becomes a mission_task with:
external_id = "RUSTSEC-YYYY-NNNN"title = advisory.titlestatus = "created"
The coding phase picks up each finding as an INT-XX item and applies the fix (bump, replace, or add ignore-with-justification). Emit COMPLETED: RUSTSEC-YYYY-NNNN when the follow-up commit lands.
Anti-patterns
- Silencing an advisory in CI without a fix commit. Advisories aren't a code style violation — they're a claim your code is exposed. Fix or explicitly accept.
- Bumping to a beta version to "fix" it. Betas can regress. Prefer a patched stable; if none exists, wait or fork.
- Running
cargo auditonly in CI, never locally. Every commit that changes Cargo.lock should trigger a local run.