• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

tari-project / tari / 36421264328
71%

Build:
DEFAULT BRANCH: development
Ran 28 Sep 2026 01:10PM UTC
Jobs 1
Files 782
Run time 2min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

28 Sep 2026 12:20PM UTC coverage: 64.02% (+0.3%) from 63.682%
36421264328

push

github

web-flow
chore(ci): run the supply-chain policy on every pull request (#8053)

Description
---

Ports tari-project/tari-ootle#2669 to this repository. Tari had no
`deny.toml` at all, so nothing checked the bans, licenses or sources of
the dependency tree.

- **New `deny.toml`** with the same policy as ootle: permissive licenses
only, `*` version requirements denied (path dependencies exempt for
`publish = false` crates), and crates.io the only allowed registry, with
git sources denied unless they are listed.
- **New `.github/workflows/cargo-deny.yml`** (job `cargo deny`) runs
`cargo deny --all-features check bans licenses sources`.
- **All workspaces are checked, not just the root.** It runs once per
tracked `Cargo.lock`, which covers the root plus
`applications/minotari_ledger_wallet/comms_testing` and
`applications/minotari_ledger_wallet/wallet`. `audit.yml` already notes
that a root-only scan makes the excluded workspaces look covered when
they are not. Because the list comes from the repo rather than a
hand-kept list, a new excluded workspace is covered automatically.
- **Triggers:** `pull_request` and `merge_group` have **no path
filter**. A required check that a path filter skips stays pending and
blocks the merge. `push` is limited to `development`, `nextnet` and
`mainnet`, and only runs when manifests, lockfiles or the policy change.
- **Pinned tools:** cargo-deny 0.20.2 is installed with
`taiki-e/install-action`, which is pinned by SHA.
- **`audit.yml` is unchanged** apart from a comment pointing to the new
workflow. Advisories stay there and are **not** part of this gate (see
below).

**What running it found.** Each was fixed or recorded:

- **A git source:** `liblmdb-sys` from
`https://github.com/tari-project/lmdb-rs` (pinned by tag). It is now
listed in `allow-git`, with `unknown-git = "deny"`.
- **Three licenses not on the allow list, all permissive:**
  - `0BSD`: `mock_instant`, via `log4rs`.
  - `bzip2-1.0.6`: `libbz2-rs-sys`, via `bzip2` <- `pg... (continued)

91438 of 142828 relevant lines covered (64.02%)

288316.93 hits per line

Coverage Regressions

Lines Coverage ∆ File
7
72.13
-0.59% comms/core/src/connectivity/manager.rs
5
55.58
-0.62% base_layer/core/src/base_node/comms_interface/inbound_handlers.rs
5
56.34
0.81% base_layer/core/src/chain_storage/lmdb_db/lmdb_db.rs
4
96.14
0.71% base_layer/core/src/validation/block_body/test.rs
4
87.67
-1.83% base_layer/transaction_components/src/validation/helpers.rs
2
66.1
7.97% base_layer/core/src/chain_storage/blockchain_database.rs
2
86.94
-0.1% base_layer/core/src/proof_of_work/cuckaroo_pow.rs
1
98.24
-0.15% base_layer/core/src/proof_of_work/monero_rx/merkle_tree.rs
1
82.94
-0.2% comms/core/src/noise/socket.rs
1
69.41
0.0% comms/dht/src/connectivity/mod.rs
Jobs
ID Job ID Ran Files Coverage
1 36421264328.1 28 Sep 2026 01:10PM UTC 782
64.02
GitHub Action Run
Source Files on build 36421264328
  • Tree
  • List 782
  • Changed 22
  • Source Changed 0
  • Coverage Changed 22
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #36421264328
  • 93c4c29f on github
  • Prev Build on development (#36403759382)
  • Next Build on development (#36429950117)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc