forked from actions-rs/audit-check
-
Notifications
You must be signed in to change notification settings - Fork 14
Closed
Description
Copying actions-rs#163 to this fork.
Description
This action calls cargo generate-lockfile, which overwrites Cargo.lock according to cargo docs1
This command will create the Cargo.lock lockfile for the current package or workspace. If the lockfile already exists, it will be rebuilt with the latest available version of every package.
This negates the purpose of having a checked-in lockfile.
Proposed Fix
Rather than call cargo generate-lockfile, call cargo metadata --format-version=1 >/dev/null instead.
Footnotes
mweber15 and pranc1ngpegasus
Metadata
Metadata
Assignees
Labels
No labels