From b1555570b3310d39345d590c997796b2726cf264 Mon Sep 17 00:00:00 2001 From: Michael Watzko Date: Fri, 19 Mar 2021 12:00:42 +0100 Subject: [PATCH] Add cargo deny to check dependencies for license disagreements TLDR: deny copyleft, deny unknown, allow only MIT, Apache-2.0 and BSD-3-Clause --- .github/workflows/rust.yml | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/.github/workflows/rust.yml b/.github/workflows/rust.yml index b2446597..aa2b19df 100644 --- a/.github/workflows/rust.yml +++ b/.github/workflows/rust.yml @@ -186,4 +186,11 @@ jobs: uses: coverallsapp/github-action@master with: github-token: ${{ secrets.GITHUB_TOKEN }} - path-to-lcov: './lcov.info' \ No newline at end of file + path-to-lcov: './lcov.info' + + cargo-deny: + name: Check license and vulnerabilities + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v2 + - uses: EmbarkStudios/cargo-deny-action@v1 \ No newline at end of file