Skip to content

Install Rust with rustup directly instead of dtolnay/rust-toolchain - #1089

Merged
nedtwigg merged 1 commit into
mainfrom
ci/rustup-direct
Oct 9, 2026
Merged

nedtwigg merged 1 commit into
mainfrom
ci/rustup-direct

Conversation

@nedtwigg

@nedtwigg nedtwigg commented Oct 9, 2026

Copy link
Copy Markdown
Member

Replaces #1088. Every PR's Workflow Lint currently fails because dtolnay/rust-toolchain force-pushed its stable branch at 2026-10-09 02:03Z, leaving our SHA pin 89b12181 reachable from no branch, which zizmor's impostor-commit audit reports as an error.

That force-push is not a compromise: it is how the action is released. Every branch (stable, 1.99, …) is master plus one generated commit, rebuilt and force-pushed whenever master changes, so any SHA pin into stable breaks again on the next upstream change. The push was by dtolnay, the new commits are GPG-signed by him, and the change (dtolnay/rust-toolchain#187) only hardens input handling.

Rather than re-pin, this drops the action. rustup is preinstalled on every GitHub-hosted runner, so the two ci.yml jobs and the release.yml matrix run rustup toolchain install stable --profile minimal --no-self-update (plus --target in the release) and rustup default stable. That removes a third-party action and its Renovate churn. Measured on #1088's run, the action's own overhead beyond the rustup download was about 1–2s per job, so speed is unchanged.

Dropped with the action: its five-attempt retry around the install (rustup still retries individual downloads), and its CARGO_INCREMENTAL=0 / CARGO_TERM_COLOR=always defaults. swatinem/rust-cache already sets CARGO_INCREMENTAL=0 in the job it caches.

release.yml runs only on v* tags, so this PR's CI exercises the ci.yml steps; the release step is the same command plus --target.

🤖 Generated with Claude Code

dtolnay/rust-toolchain rebuilds and force-pushes its `stable` branch on every
upstream change, so a SHA pin into it stops being reachable from any branch and
zizmor's impostor-commit audit fails every PR's Workflow Lint. rustup ships on
all GitHub-hosted runners, so the three call sites run it themselves and the
third-party action goes away.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Deploying mouseterm with  Cloudflare Pages  Cloudflare Pages

Latest commit: 6100ab9
Status: ✅  Deploy successful!
Preview URL: https://132c370f.mouseterm.pages.dev
Branch Preview URL: https://ci-rustup-direct.mouseterm.pages.dev

View logs

@nedtwigg
nedtwigg merged commit ca6b5b8 into main Oct 9, 2026
13 checks passed
@nedtwigg
nedtwigg deleted the ci/rustup-direct branch October 9, 2026 15:31

This branch is waiting to be deployed

1 waiting deployment
hosted-preview — 6100ab93 Waiting Oct 9, 2026 by nedtwigg via cleanup #1264
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants