From 57759f81b6d486452f74c6b499684e75ed6ef014 Mon Sep 17 00:00:00 2001 From: Nicolas Dreno Date: Sat, 12 Sep 2026 11:55:23 +0200 Subject: [PATCH 1/2] Publish as barbacane-libinjection; add a release workflow The crate names libinjectionrs and libinjection are already taken on crates.io (by the upstream original and an FFI-bindings crate), so this fork publishes under barbacane-libinjection. The library target keeps the name libinjectionrs, and internal path deps use `package = "barbacane-libinjection"`, so no source using `libinjectionrs::` changes. Add .github/workflows/release.yml: on a version tag it checks the tag matches Cargo.toml and runs `cargo publish`, using a CARGO_REGISTRY_TOKEN secret (org-level, or set on this repo). --- .github/workflows/release.yml | 36 +++++++++++++++++++++++++++++++++++ benches/Cargo.toml | 2 +- comparison-bin/Cargo.toml | 2 +- fuzz/Cargo.toml | 1 + libinjection-debug/Cargo.toml | 2 +- libinjectionrs/Cargo.toml | 6 +++--- 6 files changed, 43 insertions(+), 6 deletions(-) create mode 100644 .github/workflows/release.yml diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml new file mode 100644 index 0000000..1ea73f1 --- /dev/null +++ b/.github/workflows/release.yml @@ -0,0 +1,36 @@ +name: Release + +# Publishes barbacane-libinjection to crates.io when a version tag is pushed. +# The tag must match the version in Cargo.toml. Requires a CARGO_REGISTRY_TOKEN +# secret (org-level, or set on this repo). + +on: + push: + tags: ['v*'] + +permissions: + contents: read + +jobs: + publish: + name: Publish to crates.io + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v5 + with: + persist-credentials: false + + - uses: dtolnay/rust-toolchain@stable + + - name: Check tag matches Cargo.toml version + run: | + TAG="${GITHUB_REF#refs/tags/v}" + VER="$(sed -n 's/^version = "\([^"]*\)".*/\1/p' Cargo.toml | head -1)" + if [ "$TAG" != "$VER" ]; then + echo "::error::tag v$TAG does not match Cargo.toml version $VER" + exit 1 + fi + echo "Publishing version $VER" + + - name: Publish + run: cargo publish -p barbacane-libinjection --token "${{ secrets.CARGO_REGISTRY_TOKEN }}" diff --git a/benches/Cargo.toml b/benches/Cargo.toml index b3947b8..d891628 100644 --- a/benches/Cargo.toml +++ b/benches/Cargo.toml @@ -23,7 +23,7 @@ harness = false path = "differential_bench.rs" [dependencies] -libinjectionrs = { path = "../libinjectionrs" } +libinjectionrs = { path = "../libinjectionrs", package = "barbacane-libinjection" } criterion.workspace = true [build-dependencies] diff --git a/comparison-bin/Cargo.toml b/comparison-bin/Cargo.toml index cea307c..de5fcb7 100644 --- a/comparison-bin/Cargo.toml +++ b/comparison-bin/Cargo.toml @@ -9,7 +9,7 @@ name = "compare" path = "src/main.rs" [dependencies] -libinjectionrs = { path = "../libinjectionrs" } +libinjectionrs = { path = "../libinjectionrs", package = "barbacane-libinjection" } clap = { version = "4.4", features = ["derive"] } serde = { version = "1.0", features = ["derive"] } serde_json = "1.0" diff --git a/fuzz/Cargo.toml b/fuzz/Cargo.toml index 972804e..74a1ce7 100644 --- a/fuzz/Cargo.toml +++ b/fuzz/Cargo.toml @@ -12,6 +12,7 @@ libfuzzer-sys = "0.4" [dependencies.libinjectionrs] path = "../libinjectionrs" +package = "barbacane-libinjection" [build-dependencies] bindgen = "0.69" diff --git a/libinjection-debug/Cargo.toml b/libinjection-debug/Cargo.toml index 4ee85fa..bb65a11 100644 --- a/libinjection-debug/Cargo.toml +++ b/libinjection-debug/Cargo.toml @@ -8,7 +8,7 @@ description = "Comprehensive debugging tool for libinjection tokenization" [workspace] [dependencies] -libinjectionrs = { path = "../libinjectionrs" } +libinjectionrs = { path = "../libinjectionrs", package = "barbacane-libinjection" } clap = { version = "4.0", features = ["derive"] } serde = { version = "1.0", features = ["derive"] } serde_json = "1.0" diff --git a/libinjectionrs/Cargo.toml b/libinjectionrs/Cargo.toml index 2a8e031..671e5c1 100644 --- a/libinjectionrs/Cargo.toml +++ b/libinjectionrs/Cargo.toml @@ -1,11 +1,11 @@ [package] -name = "libinjectionrs" +name = "barbacane-libinjection" version.workspace = true edition.workspace = true authors.workspace = true license.workspace = true -repository.workspace = true -description = "Rust port of libinjection - SQL/XSS injection detection library" +repository = "https://github.com/barbacane-dev/libinjectionrs" +description = "A memory-safe Rust port of libinjection (SQL injection and XSS detection), differential-tested against the C library" readme = "README.md" keywords = ["security", "sql-injection", "xss", "detection", "web-security"] categories = ["web-programming", "parser-implementations"] From 27e37730fbff28e0e9bb8de7679b231a911481cb Mon Sep 17 00:00:00 2001 From: Nicolas Dreno Date: Sat, 12 Sep 2026 12:04:33 +0200 Subject: [PATCH 2/2] CI: reference the renamed package in the coverage job --- .github/workflows/ci.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 7977620..aa4be46 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -49,7 +49,7 @@ jobs: tool: cargo-llvm-cov - name: Measure coverage run: | - cargo llvm-cov --no-report -p libinjectionrs --lib + cargo llvm-cov --no-report -p barbacane-libinjection --lib cargo llvm-cov report --summary-only | tee coverage.txt cargo llvm-cov report --lcov --output-path lcov.info - name: Publish summary