Skip to content

ci: install Rust with rustup instead of dtolnay/rust-toolchain - #231

Merged
arcjet-rei merged 1 commit into
mainfrom
rei/fix/ENG-1395-rustup-without-action
Oct 3, 2026
Merged

arcjet-rei merged 1 commit into
mainfrom
rei/fix/ENG-1395-rustup-without-action

Conversation

@arcjet-rei

Copy link
Copy Markdown
Contributor

Dependabot's 7-day cooldown (#227) is measured from a release, and dtolnay/rust-toolchain has no version tags: it ships through branches, so gravity pinned it to a bare commit and Dependabot proposed each new commit within a day or two (#221, #223, #225).

The action also installed a toolchain the build never used. It installed and defaulted to stable, while rust-toolchain.toml selects 1.90.0, which rustup then downloaded on first use. The runner image already ships rustup, so this replaces the action with rustup toolchain install --no-self-update, which installs the toolchain, components and targets pinned in rust-toolchain.toml. The CARGO_INCREMENTAL=0 and CARGO_TERM_COLOR=always that the action exported are now set on the job.

With this change, every action in the workflow is pinned to a tagged release, which the cooldown covers.

🤖 Generated with Claude Code

dtolnay/rust-toolchain has no version tags, so it is pinned to a bare
commit and Dependabot's 7-day cooldown, which is measured from a
release, never delayed its updates. It also installed a stable toolchain
the build never used: rust-toolchain.toml selects 1.90.0, which rustup
then installed on first use.

The runner image already ships rustup, so install the toolchain pinned
in rust-toolchain.toml directly, and set the CARGO_INCREMENTAL and
CARGO_TERM_COLOR values the action exported on the job.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@arcjet-rei
arcjet-rei requested a review from a team as a code owner October 3, 2026 16:44

@arcjet-review arcjet-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Arcjet Review — 🟡 Medium Risk

Decision: Checked

Rationale: This PR changes a GitHub Actions CI workflow, which triggers CI/CD review attention, but the change is narrowly scoped and understandable: it removes the dtolnay/rust-toolchain action and uses the runner-provided rustup to install the repository-pinned Rust toolchain, while preserving the Cargo environment variables previously provided by the action. No hardcoded secrets, untrusted input handling, auth changes, or unsafe command construction were introduced.

Summary of Changes

Updates the CI workflow to install Rust via rustup toolchain install --no-self-update instead of the dtolnay/rust-toolchain action, and sets Cargo-related environment variables at the job level.

Escalation Triggers

  • CI/CD Pipeline: The PR modifies .github/workflows/ci.yml, changing how the CI job installs the Rust toolchain.

Review Focus Areas

Notes

The AI assessed this PR as approvable, but the trust level (1) does not allow auto-approval. A human reviewer must approve this PR.

Review: 5cf8e5ad | Model: openai/gpt-5.5 | Powered by Arcjet Review

@arcjet-review arcjet-review Bot removed the needs review Awaiting human review label Oct 3, 2026
@arcjet-rei
arcjet-rei merged commit 43e1ecd into main Oct 3, 2026
4 checks passed
@arcjet-rei
arcjet-rei deleted the rei/fix/ENG-1395-rustup-without-action branch October 3, 2026 16:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants