Rust auto remediation support

Why are we doing this work

Rust adoption keeps growing, particularly in performance-sensitive and infrastructure code. Extending auto-remediation to support Cargo lets Rust projects benefit from automatic MR creation for vulnerable dependency upgrades, the same way Ruby/Bundler and Java/Maven projects do today.

This is part of &19244 (Auto-remediation with automatic bumping of dependencies - GA).

Implementation plan

Package manager: cargo (Cargo.toml, Cargo.lock). Version bumping is handled by the dependabot-cargo gem.

Updater

  • Add cargo/Dockerfile - mirrors bundler/Dockerfile/maven/Dockerfile with ARG ECOSYSTEM=cargo. Base image needs a Rust toolchain (rustup/cargo) since dependabot-cargo invokes Cargo tooling at runtime
  • Add a cargo build target to docker-bake.hcl
  • Add a release job in .gitlab/ci/jobs/release-ecosystems.yml
  • No Ruby code changes needed - PackageManager enum and EcosystemLoader already support cargo

Orchestrator

No changes required. schema.json already lists cargo as a valid package-manager value. Routing to the correct updater image is automatic.

GitLab (Rails)

  • scheduler_service.rb - add 'cargo' to SUPPORTED_PACKAGE_MANAGERS
  • job_builder.rb - add a 'cargo' => 'cargo' entry to PACKAGE_MANAGER_MAPPING
  • doc/user/application_security/remediate/auto_remediation.md - add a Rust/Cargo row to the supported package managers table

Non-functional requirements

  • Documentation: update auto_remediation.md to add Rust (Cargo.toml, Cargo.lock) to the supported package managers table
  • Feature flag: gated behind existing dependency_management_auto_remediation flag - no new flag needed
  • Performance: no impact - Cargo follows the same workload pattern as Bundler/Maven
  • Testing:
    • Updater: extend ecosystem_loader_spec.rb load table; add spec/fixtures/cargo/ fixture project; add Cargo contexts to file_fetcher_command_spec.rb, file_parser_command_spec.rb, file_updater_command_spec.rb
    • E2e: run the cargo-updater container against a real GitLab project with a known vulnerable dependency and verify output.json and MR creation end-to-end

Verification steps

  1. Enable dependency_management_auto_remediation feature flag on a test project using Cargo
  2. Ensure dependency scanning is enabled and producing results with at least one vulnerability that has a known fix version
  3. Run a pipeline and confirm an auto-remediation MR is created that bumps the vulnerable dependency in Cargo.toml/Cargo.lock
  4. Confirm the MR title, description, and branch name follow the same format as Bundler/Maven MRs
  5. Merge the MR and confirm the vulnerability is resolved in the next pipeline scan
Edited by Oscar Tovar