chore: add GitHub automation and fix rand vulnerability
Code Quality / quality-checks (push) Has been cancelled
Security Scan / security-audit (push) Has been cancelled

GitHub Actions:
- Add Dependabot for weekly dependency updates (cargo, github-actions)
- Add PR labeler workflow with file-based auto-labeling
- Add issue/PR templates (bug report, feature request, PR template)
- Fix release.yml artifact paths and labeler.yml config syntax
Security:
- Upgrade rand 0.8 → 0.10 to fix RUSTSEC-2026-0097 unsoundness
- Update screenshot.rs for rand 0.10 API (thread_rng → rng, gen_range → random_range)
This commit is contained in:
2026-04-11 18:18:41 +02:00
parent 7a0adc4d82
commit c6ec65c851
10 changed files with 379 additions and 46 deletions
+3 -1
View File
@@ -3,6 +3,8 @@ name = "rustlock"
version = "0.1.0"
edition = "2021"
license = "GPL-3.0-or-later"
authors = ["Jory Severijnse"]
description = "A high-performance Wayland screen locker"
[dependencies]
smithay-client-toolkit = { version = "0.19", default-features = false, features = ["calloop", "xkbcommon"] }
@@ -27,7 +29,7 @@ zbus = { version = "5.14", default-features = false, features = ["tokio"] }
mpris = "2.0"
tokio = { version = "1.51", default-features = false, features = ["rt", "rt-multi-thread", "macros", "time", "sync"] }
num-traits = { version = "0.2" }
rand = { version = "0.8" }
rand = { version = "0.10" }
reqwest = { version = "0.12", default-features = false, features = ["blocking", "rustls-tls"], optional = true }
image = { version = "0.25", default-features = false, features = ["png", "jpeg"] }
fastblur = "0.1"