Skip to content

chore(deps): bump actions-rust-lang/setup-rust-toolchain from 1.17.0 to 2.0.0 in the github-actions group - #252

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-037a365596
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-037a365596

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 1 update: actions-rust-lang/setup-rust-toolchain.

Updates actions-rust-lang/setup-rust-toolchain from 1.17.0 to 2.0.0

Release notes

Sourced from actions-rust-lang/setup-rust-toolchain's releases.

v2.0.0

What's Changed

  • Use CARGO_BUILD_WARNINGS for enforcing warning free compilations (#98) This is a new variable supported by cargo 1.97+ and sets the build.warnings config. It allows removing the RUSTFLAGS="-D warnings" default, which will improve compatibility with target.*.rustflags and .cargo/config.toml files.

    This adds a new build-warnings input to configure the value for the build.warnings config.

  • Add error matcher for Rust panics This will highlight the location of the panic location during tests.

  • Reuse output of rustc --version --verbose calls (#103 by @​ChihweiLHBird)

New Contributors

Full Changelog: actions-rust-lang/setup-rust-toolchain@v1.17.0...v2.0.0

Changelog

Sourced from actions-rust-lang/setup-rust-toolchain's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased]

[2.0.0] - 2026-09-07

  • Use CARGO_BUILD_WARNINGS for enforcing warning free compilations (#98) This is a new variable supported by cargo 1.97+ and sets the build.warnings config. It allows removing the RUSTFLAGS="-D warnings" default, which will improve compatibility with target.*.rustflags and .cargo/config.toml files.

    This adds a new build-warnings input to configure the value for the build.warnings config.

  • Add error matcher for Rust panics This will highlight the location of the panic location during tests.

  • Reuse output of rustc --version --verbose calls (#103 by @​ChihweiLHBird)

[1.17.0] - 2026-06-25

  • Add new parameter cache-targets that is propagated to Swatinem/rust-cache as cache-targets (#84). This allows disabling caching of the workspace target directory, e.g. when using sccache, while keeping the rest of the cache enabled.

[1.16.1] - 2026-05-08

  • Renamed internally used variable to avoid clashes with globally existing variables. This fixes the interference of the TOOLCHAIN variable as reported in #91.

[1.16.0] - 2026-04-13

  • Add new parameter cache-save-if that is propagated to Swatinem/rust-cache as save-if (#90 by @​ChanTsune)

[1.15.4] - 2026-03-15

  • Bump Swatinem/rust-cache from 2.8.2 to 2.9.1 (#87 by @​hyperfinitism) This gets rid of the warnings about Node.js 20.

[1.15.3] - 2026-03-01

  • Bump Swatinem/rust-cache from 2.8.1 to 2.8.2

[1.15.2] - 2025-10-04

  • Fix: Run the version detection steps in the selected rust-src-dir directory. This should enable the version selection even without a default toolchain installed. Fixes #74.

[1.15.1] - 2025-09-23

... (truncated)

Commits
  • ecabd13 Prepare changelog for 2.0.0 release
  • dc00391 Add error matcher for Rust panics
  • 70de7eb Merge pull request #103 from ChihweiLHBird/reuse-rustc-verbose-output
  • c420b69 Merge pull request #105 from actions-rust-lang/use-build-warnings
  • d94d10a Use CARGO_BUILD_WARNINGS for enforcing warning free compilations
  • 34430aa Reuse rustc verbose output instead of invoking rustc three times.
  • 0267444 Merge pull request #102 from actions-rust-lang/dependabot/github_actions/Swat...
  • 5fa2882 Bump Swatinem/rust-cache from 2.9.1 to 2.9.2
  • 8439c15 Merge pull request #100 from actions-rust-lang/dependabot/github_actions/acti...
  • c8f944a Bump actions/checkout from 7.0.0 to 7.0.1
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Summary by CodeRabbit

  • Chores
    • Updated Rust toolchain setup across automated audit, benchmarking, CI, coverage, and linting workflows.
    • Pinned the workflows to the newer toolchain setup action version.

Bumps the github-actions group with 1 update: [actions-rust-lang/setup-rust-toolchain](https://github.com/actions-rust-lang/setup-rust-toolchain).


Updates `actions-rust-lang/setup-rust-toolchain` from 1.17.0 to 2.0.0
- [Release notes](https://github.com/actions-rust-lang/setup-rust-toolchain/releases)
- [Changelog](https://github.com/actions-rust-lang/setup-rust-toolchain/blob/main/CHANGELOG.md)
- [Commits](actions-rust-lang/setup-rust-toolchain@166cdcf...ecabd13)

---
updated-dependencies:
- dependency-name: actions-rust-lang/setup-rust-toolchain
  dependency-version: 2.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github-actions labels Sep 14, 2026
@dependabot
dependabot Bot requested a review from acgetchell as a code owner September 14, 2026 10:09
@acgetchell

Copy link
Copy Markdown
Owner

@coderabbitai review

@github-actions
github-actions Bot enabled auto-merge (squash) September 14, 2026 10:09
@coderabbitai

coderabbitai Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: 07b2b5e1-e161-43c0-96d9-53de165f9701

📥 Commits

Reviewing files that changed from the base of the PR and between 0215e65 and 1c52c3d.

📒 Files selected for processing (5)
  • .github/workflows/audit.yml
  • .github/workflows/benchmarks.yml
  • .github/workflows/ci.yml
  • .github/workflows/codecov.yml
  • .github/workflows/rust-clippy.yml

Included review availability: 3 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 4 reviews per hour.


📝 Walkthrough

Walkthrough

Five GitHub Actions workflows update actions-rust-lang/setup-rust-toolchain from v1.17.0 to the pinned v2.0.0 revision.

Changes

Rust toolchain action update

Layer / File(s) Summary
Update workflow action pins
.github/workflows/audit.yml, .github/workflows/benchmarks.yml, .github/workflows/ci.yml, .github/workflows/codecov.yml, .github/workflows/rust-clippy.yml
The workflows now use the pinned v2.0.0 Rust toolchain setup action instead of v1.17.0.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 1c52c

All reviewed workflows receive the intended pinned action update, with no concrete merge-blocking risk identified.

🚥 Pre-merge checks | ✅ 2 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning Issue #74 requires a GitHub Actions workflow for exact-arithmetic benchmark regression detection. The workflow must save main Criterion baselines as 30-day artifacts, download the latest main arti… Add the workflow and automated validation required by issue #74. Configure push-to-main baseline artifacts with 30-day retention, pull-request artifact download and Criterion comparison, and non-blocking job-summary reporting.
Out of Scope Changes check ⚠️ Warning The changes update actions-rust-lang/setup-rust-toolchain from 1.17.0 to 2.0.0 in audit.yml, benchmarks.yml, ci.yml, codecov.yml, and rust-clippy.yml. These dependency updates have no demo… Remove these unrelated toolchain action updates from this pull request, or link them to a requirement that explicitly covers the dependency update.
✅ Passed checks (2 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately identifies the dependency update from actions-rust-lang/setup-rust-toolchain 1.17.0 to 2.0.0 in GitHub Actions. It clearly summarizes the main change.
Full details: Linked Issues check

Explanation

Issue #74 requires a GitHub Actions workflow for exact-arithmetic benchmark regression detection. The workflow must save main Criterion baselines as 30-day artifacts, download the latest main artifact for pull requests, compare with --baseline, and report warning-only regressions in the job summary. The PR summary shows only actions-rust-lang/setup-rust-toolchain updates in five existing workflows. It does not show implementation or tests for these requirements.

Full details: Out of Scope Changes check

Explanation

The changes update actions-rust-lang/setup-rust-toolchain from 1.17.0 to 2.0.0 in audit.yml, benchmarks.yml, ci.yml, codecov.yml, and rust-clippy.yml. These dependency updates have no demonstrated connection to the exact-arithmetic benchmark regression workflow required by issue #74.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/github_actions/github-actions-037a365596

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

coderabbitai Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github-actions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant