Repository navigation
ci: install Rust with rustup instead of dtolnay/rust-toolchain - #231
Conversation
dtolnay/rust-toolchain has no version tags, so it is pinned to a bare commit and Dependabot's 7-day cooldown, which is measured from a release, never delayed its updates. It also installed a stable toolchain the build never used: rust-toolchain.toml selects 1.90.0, which rustup then installed on first use. The runner image already ships rustup, so install the toolchain pinned in rust-toolchain.toml directly, and set the CARGO_INCREMENTAL and CARGO_TERM_COLOR values the action exported on the job. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Arcjet Review — 🟡 Medium Risk
Decision: Checked
Rationale: This PR changes a GitHub Actions CI workflow, which triggers CI/CD review attention, but the change is narrowly scoped and understandable: it removes the dtolnay/rust-toolchain action and uses the runner-provided rustup to install the repository-pinned Rust toolchain, while preserving the Cargo environment variables previously provided by the action. No hardcoded secrets, untrusted input handling, auth changes, or unsafe command construction were introduced.
Summary of Changes
Updates the CI workflow to install Rust via rustup toolchain install --no-self-update instead of the dtolnay/rust-toolchain action, and sets Cargo-related environment variables at the job level.
Escalation Triggers
- CI/CD Pipeline: The PR modifies
.github/workflows/ci.yml, changing how the CI job installs the Rust toolchain.
Review Focus Areas
- Confirm that the checkout step runs before this command and that
rust-toolchain.tomlis present in the working directory whenrustup toolchain install --no-self-updateexecutes.
Without the toolchain file available, rustup may not install the intended pinned toolchain, components, and targets.
Notes
The AI assessed this PR as approvable, but the trust level (1) does not allow auto-approval. A human reviewer must approve this PR.
Review: 5cf8e5ad | Model: openai/gpt-5.5 | Powered by Arcjet Review
Dependabot's 7-day cooldown (#227) is measured from a release, and
dtolnay/rust-toolchainhas no version tags: it ships through branches, so gravity pinned it to a bare commit and Dependabot proposed each new commit within a day or two (#221, #223, #225).The action also installed a toolchain the build never used. It installed and defaulted to
stable, whilerust-toolchain.tomlselects 1.90.0, which rustup then downloaded on first use. The runner image already ships rustup, so this replaces the action withrustup toolchain install --no-self-update, which installs the toolchain, components and targets pinned inrust-toolchain.toml. TheCARGO_INCREMENTAL=0andCARGO_TERM_COLOR=alwaysthat the action exported are now set on the job.With this change, every action in the workflow is pinned to a tagged release, which the cooldown covers.
🤖 Generated with Claude Code