name: Security
on:
push:
branches:
pull_request:
branches:
schedule:
- cron: "0 6 * * 1" # Weekly on Monday 6am UTC
permissions:
contents: read
env:
CARGO_TERM_COLOR: always
jobs:
deny:
name: License & Supply Chain
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
persist-credentials: false
- uses: EmbarkStudios/cargo-deny-action@3fd3802e88374d3fe9159b834c7714ec57d6c979 # v2.0.15
with:
command: check advisories licenses sources