fix(security): drop jwt-go via first-party Apple auth, bump yoke-derive, grant checks:write to rust audit

Refs WAR-10

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
Matthew Meszaros
2026-10-04 18:36:28 +00:00
co-authored by Devin AI
parent 7e8bad00e6
commit 0ea856537e
9 changed files with 354 additions and 29 deletions
+5
View File
@@ -86,6 +86,11 @@ jobs:
rust:
name: Rust Dependencies
runs-on: ubuntu-latest
# audit-check reports its result as a check run, which the workflow-wide
# read-only token cannot create.
permissions:
contents: read
checks: write
steps:
- uses: actions/checkout@v4
- uses: rustsec/audit-check@v2