Skip to content

ci: pin dtolnay/rust-toolchain action, keep channels via toolchain input - #451

Open
arcaven wants to merge 1 commit into
Zious11:developfrom
ArcavenAE:ci/pin-dtolnay-upstream
Open

ci: pin dtolnay/rust-toolchain action, keep channels via toolchain input#451
arcaven wants to merge 1 commit into
Zious11:developfrom
ArcavenAE:ci/pin-dtolnay-upstream

Conversation

@arcaven

@arcaven arcaven commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

This closes the one intentional gap in your action-pin-gate: the dtolnay/rust-toolchain refs are the only remote actions CI runs from a mutable ref, and the reason recorded in the allowlist comment (pinning would defeat rolling-channel tracking) no longer holds. The action's master branch accepts the channel through an explicit toolchain input (required, per its action.yml), so a commit pin and channel tracking now coexist. Recent npm-ecosystem supply-chain incidents made mutable action refs worth closing out where the cost is this low.

What changes: all 9 dtolnay/rust-toolchain sites (8 in ci.yml, 1 in release.yml) move from @stable/@nightly to a commit pin (2c7215f, master as of 2026-08-04) with the channel passed via with: toolchain:. The nightly doc-tests job already passed its dated nightly through that input, so it only changes the ref. The gate's allowlist empties, and its exemption comment is updated to say why the exemption retired rather than deleted quietly.

Counted at this branch head:

git diff <base>..HEAD -- .github/workflows/ | grep -c '^-.*dtolnay/rust-toolchain@'   # 9

Verification: the action-pin-gate script from this branch's ci.yml, extracted and run against the tree with ALLOWLIST="", exits 0. The toolchain input is declared required: true in the pinned commit's action.yml, so a future site added without a channel fails loudly at startup rather than silently defaulting.

One judgment call to flag: the pin is to the action's master branch at a dated commit (dtolnay publishes no releases), and master has advanced since. If you would rather track a different commit, or keep your documented exemption instead, happy to adjust or close; the same change has been running green on our fork since 2026-08-04.

…put (#1)

The stable and nightly refs were the repo's two documented pin-gate
exemptions because the ref name carried the channel. Pinning the action
commit (2c7215f, master 2026-08-04) and selecting the channel through
the explicit toolchain input keeps rolling-channel semantics while
closing the mutable-ref surface. The action-pin-gate allowlist is now
empty and the gate validates every remote ref. Prepares for org-level
sha_pinning_required, which has no allowlist mechanism.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant