Skip to content

Record cargo-vet wildcard audit for trusted publisher #1365

@divergentdave

Description

@divergentdave

cargo-vet added support for trusted publishing in wildcard audits in mozilla/cargo-vet#671, however this has not been included in a new release yet. We switched over to using trusted publishing in #1356, and published 0.16.8 using this. Our existing wildcard audit is only for releases made by our automation user. Once a new version of cargo-vet is available, we should upgrade and publish a new wildcard audit. Publishing a wildcard audit for a trusted publisher might force others importing our audits to upgrade cargo-vet as well, so I'm wary about using this feature before a release is cut.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions