ci: pin dtolnay/rust-toolchain action, keep channels via toolchain input - #451
Open
arcaven wants to merge 1 commit into
Open
ci: pin dtolnay/rust-toolchain action, keep channels via toolchain input#451arcaven wants to merge 1 commit into
arcaven wants to merge 1 commit into
Conversation
…put (#1) The stable and nightly refs were the repo's two documented pin-gate exemptions because the ref name carried the channel. Pinning the action commit (2c7215f, master 2026-08-04) and selecting the channel through the explicit toolchain input keeps rolling-channel semantics while closing the mutable-ref surface. The action-pin-gate allowlist is now empty and the gate validates every remote ref. Prepares for org-level sha_pinning_required, which has no allowlist mechanism.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This closes the one intentional gap in your action-pin-gate: the dtolnay/rust-toolchain refs are the only remote actions CI runs from a mutable ref, and the reason recorded in the allowlist comment (pinning would defeat rolling-channel tracking) no longer holds. The action's master branch accepts the channel through an explicit
toolchaininput (required, per its action.yml), so a commit pin and channel tracking now coexist. Recent npm-ecosystem supply-chain incidents made mutable action refs worth closing out where the cost is this low.What changes: all 9 dtolnay/rust-toolchain sites (8 in ci.yml, 1 in release.yml) move from
@stable/@nightlyto a commit pin (2c7215f, master as of 2026-08-04) with the channel passed viawith: toolchain:. The nightly doc-tests job already passed its dated nightly through that input, so it only changes the ref. The gate's allowlist empties, and its exemption comment is updated to say why the exemption retired rather than deleted quietly.Counted at this branch head:
Verification: the action-pin-gate script from this branch's ci.yml, extracted and run against the tree with
ALLOWLIST="", exits 0. Thetoolchaininput is declaredrequired: truein the pinned commit's action.yml, so a future site added without a channel fails loudly at startup rather than silently defaulting.One judgment call to flag: the pin is to the action's master branch at a dated commit (dtolnay publishes no releases), and master has advanced since. If you would rather track a different commit, or keep your documented exemption instead, happy to adjust or close; the same change has been running green on our fork since 2026-08-04.