Rust auto remediation support
Why are we doing this work
Rust adoption keeps growing, particularly in performance-sensitive and infrastructure code. Extending auto-remediation to support Cargo lets Rust projects benefit from automatic MR creation for vulnerable dependency upgrades, the same way Ruby/Bundler and Java/Maven projects do today.
This is part of &19244 (Auto-remediation with automatic bumping of dependencies - GA).
Relevant links
- Parent epic: &19244
- Auto-remediation docs: https://docs.gitlab.com/ee/user/application_security/remediate/auto_remediation.html
- Updater repo: https://gitlab.com/gitlab-org/security-products/dependency-management/updater
- Orchestrator repo: https://gitlab.com/gitlab-org/security-products/dependency-management/orchestrator
Implementation plan
Package manager: cargo (Cargo.toml, Cargo.lock). Version bumping is handled by the dependabot-cargo gem.
Updater
- Add
cargo/Dockerfile- mirrorsbundler/Dockerfile/maven/DockerfilewithARG ECOSYSTEM=cargo. Base image needs a Rust toolchain (rustup/cargo) sincedependabot-cargoinvokes Cargo tooling at runtime - Add a
cargobuild target todocker-bake.hcl - Add a release job in
.gitlab/ci/jobs/release-ecosystems.yml - No Ruby code changes needed -
PackageManagerenum andEcosystemLoaderalready supportcargo
Orchestrator
No changes required. schema.json already lists cargo as a valid package-manager value. Routing to the correct updater image is automatic.
GitLab (Rails)
scheduler_service.rb- add'cargo'toSUPPORTED_PACKAGE_MANAGERSjob_builder.rb- add a'cargo' => 'cargo'entry toPACKAGE_MANAGER_MAPPINGdoc/user/application_security/remediate/auto_remediation.md- add a Rust/Cargo row to the supported package managers table
Non-functional requirements
- Documentation: update
auto_remediation.mdto add Rust (Cargo.toml,Cargo.lock) to the supported package managers table - Feature flag: gated behind existing
dependency_management_auto_remediationflag - no new flag needed - Performance: no impact - Cargo follows the same workload pattern as Bundler/Maven
- Testing:
- Updater: extend
ecosystem_loader_spec.rbload table; addspec/fixtures/cargo/fixture project; add Cargo contexts tofile_fetcher_command_spec.rb,file_parser_command_spec.rb,file_updater_command_spec.rb - E2e: run the
cargo-updatercontainer against a real GitLab project with a known vulnerable dependency and verifyoutput.jsonand MR creation end-to-end
- Updater: extend
Verification steps
- Enable
dependency_management_auto_remediationfeature flag on a test project using Cargo - Ensure dependency scanning is enabled and producing results with at least one vulnerability that has a known fix version
- Run a pipeline and confirm an auto-remediation MR is created that bumps the vulnerable dependency in
Cargo.toml/Cargo.lock - Confirm the MR title, description, and branch name follow the same format as Bundler/Maven MRs
- Merge the MR and confirm the vulnerability is resolved in the next pipeline scan
Edited by Oscar Tovar