pkgwatch/Cargo.toml
Austin Schaefer 13a1381bdf
All checks were successful
CI / build (push) Successful in 13m17s
CI / test (push) Successful in 3m59s
CI / coverage (push) Successful in 9m22s
CI / audit (push) Successful in 16s
Add shift-left quality gates: cognitive complexity, coverage, dependency fix
Adds two new gates to the existing format/lint/test/audit pipeline
(Makefile.toml `cargo make ci`, .forgejo/workflows/ci.yml):

- Cognitive complexity via clippy's nursery cognitive_complexity lint
  (clippy.toml, threshold 15), scoped to --bins so test code's naturally
  higher branch count doesn't get gated. Went with this over the closest
  real cyclomatic-complexity tool (rust-code-analysis-cli) because that
  crate hasn't shipped a release since Jan 2023.
- Test coverage via cargo-llvm-cov, chosen over cargo-tarpaulin for
  friendlier behavior in containerized/dind CI (no ptrace). Report-only
  for now (no --fail-under-lines) since a real threshold needs real usage
  data first — see below. main.rs is excluded: it's orchestration glue
  exercised by the real end-to-end `cargo run`, not unit tests.

Getting both gates running required writing pkgwatch's first tests
(previously zero). To make the GitHub-facing modules unit-testable
without hitting real github.com/api.github.com, added `GithubEndpoints`
(src/github.rs) so checker/fetcher/verifier take injectable base URLs,
and added mockito + tempfile as dev-dependencies. Result: 27 tests,
94% region / 96% line coverage excluding main.rs.

Also: cargo audit (now wired into `cargo make ci`) immediately caught a
real, currently-open advisory (RUSTSEC-2026-0285, published days ago) in
the transitive rustls dependency — bumped 0.23.44 -> 0.23.45 to clear it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 09:16:14 +02:00

23 lines
638 B
TOML

[package]
name = "pkgwatch"
version = "0.1.0"
edition = "2024"
# Not part of a Cargo workspace — this crate is the whole repo. Declared
# explicitly (rather than just omitting it) so that checking this repo out
# as a nested git worktree can't accidentally pick up an ancestor
# directory's workspace manifest.
[workspace]
[dependencies]
anyhow = "1.0.104"
hex = "0.4.3"
regex = "1.13.1"
reqwest = { version = "0.13.5", default-features = false, features = ["blocking", "json", "rustls"] }
serde = { version = "1.0.229", features = ["derive"] }
sha2 = "0.11.0"
toml = "1.1.6"
[dev-dependencies]
mockito = "1.7.2"
tempfile = "3.27.0"