These checks never reported on main @ b312f57 because the Rust setup step died first (dtolnay/rust-toolchain@stable lock pin mismatch). Dependabot PR #294 re-pins it (d0c8d84, gh actions-lock --accept-moved), so the jobs now run, and they fail on defects already in the tree. None of them is caused by the actions bump.
| check |
failure |
cure |
cargo audit |
RUSTSEC-2026-0285 rustls 0.23.37 (TLS 1.3 handshake across encryption levels; patched >=0.23.45). Also warns RUSTSEC-2026-0253 lru 0.16.4 unsound (patched >=0.18.2). |
cargo update -p rustls (and lru if the semver range allows) |
cargo deny |
same RUSTSEC-2026-0285 |
same |
clippy (all-targets) |
7 × this function has a #[must_use] attribute with no message, but returns a type already considered as #[must_use] in verisim-provenance |
drop the redundant #[must_use] attributes |
cargo-llvm-cov (≥60%) |
error: no such command: llvm-cov |
install cargo-llvm-cov in the job (pinned action or cargo install --locked) |
Also seen: the cargo-audit action logs Unable to publish audit check! … Resource not accessible by integration because the job lacks checks: write. This doesn't change the verdict.
Acceptance criteria
🤖 Generated with Claude Code
These checks never reported on
main@b312f57because the Rust setup step died first (dtolnay/rust-toolchain@stablelock pin mismatch). Dependabot PR #294 re-pins it (d0c8d84,gh actions-lock --accept-moved), so the jobs now run, and they fail on defects already in the tree. None of them is caused by the actions bump.cargo auditrustls0.23.37 (TLS 1.3 handshake across encryption levels; patched>=0.23.45). Also warns RUSTSEC-2026-0253lru0.16.4 unsound (patched>=0.18.2).cargo update -p rustls(andlruif the semver range allows)cargo denyclippy (all-targets)this function has a #[must_use] attribute with no message, but returns a type already considered as #[must_use]inverisim-provenance#[must_use]attributescargo-llvm-cov (≥60%)error: no such command: llvm-covcargo-llvm-covin the job (pinned action orcargo install --locked)Also seen: the cargo-audit action logs
Unable to publish audit check! … Resource not accessible by integrationbecause the job lackschecks: write. This doesn't change the verdict.Acceptance criteria
Cargo.lockresolvesrustls >= 0.23.45;cargo auditandcargo denygreen onmain.clippy (all-targets)green onmainwith no newallow.cargo-llvm-cov (≥60%)runs and reports coverage onmain(green, or red only on the threshold itself).🤖 Generated with Claude Code