Repository navigation
Install Rust with rustup directly instead of dtolnay/rust-toolchain - #1089
Merged
Merged
Conversation
dtolnay/rust-toolchain rebuilds and force-pushes its `stable` branch on every upstream change, so a SHA pin into it stops being reachable from any branch and zizmor's impostor-commit audit fails every PR's Workflow Lint. rustup ships on all GitHub-hosted runners, so the three call sites run it themselves and the third-party action goes away. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Deploying mouseterm with
|
| Latest commit: |
6100ab9
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://132c370f.mouseterm.pages.dev |
| Branch Preview URL: | https://ci-rustup-direct.mouseterm.pages.dev |
dormouse-bot
approved these changes
Oct 9, 2026
nedtwigg
requested a deployment
to
hosted-preview
October 9, 2026 15:31 — with
GitHub Actions
Waiting
This branch is waiting to be deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replaces #1088. Every PR's
Workflow Lintcurrently fails becausedtolnay/rust-toolchainforce-pushed itsstablebranch at 2026-10-09 02:03Z, leaving our SHA pin89b12181reachable from no branch, which zizmor's impostor-commit audit reports as an error.That force-push is not a compromise: it is how the action is released. Every branch (
stable,1.99, …) ismasterplus one generated commit, rebuilt and force-pushed whenevermasterchanges, so any SHA pin intostablebreaks again on the next upstream change. The push was bydtolnay, the new commits are GPG-signed by him, and the change (dtolnay/rust-toolchain#187) only hardens input handling.Rather than re-pin, this drops the action. rustup is preinstalled on every GitHub-hosted runner, so the two
ci.ymljobs and therelease.ymlmatrix runrustup toolchain install stable --profile minimal --no-self-update(plus--targetin the release) andrustup default stable. That removes a third-party action and its Renovate churn. Measured on #1088's run, the action's own overhead beyond the rustup download was about 1–2s per job, so speed is unchanged.Dropped with the action: its five-attempt retry around the install (rustup still retries individual downloads), and its
CARGO_INCREMENTAL=0/CARGO_TERM_COLOR=alwaysdefaults.swatinem/rust-cachealready setsCARGO_INCREMENTAL=0in the job it caches.release.ymlruns only onv*tags, so this PR's CI exercises theci.ymlsteps; the release step is the same command plus--target.🤖 Generated with Claude Code