Skip to content

ci(rust): install the toolchain with rustup, not a blocked third-party action - #41

Merged
hyperpolymath merged 1 commit into
mainfrom
ci/rustup-not-third-party-action
Sep 30, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
ci/rustup-not-third-party-action

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

rust-ci has startup-failed on every push to main since 0f53008 (#38). The workflow file itself did not change. This repo's Actions policy is allowed_actions: selected with patterns_allowed: [], so only GitHub-owned and verified-creator actions may run. dtolnay/rust-toolchain is neither, so GitHub refuses the run before any job starts.

The action was redundant anyway. rust-toolchain.toml already pins channel = "1.97.1" plus rustfmt and clippy, and a bare rustup toolchain install on the runner reads that file.

Scope

  • Only the one step changes. The fmt / clippy / test / build / e2e / non-vacuity steps are untouched.
  • The Central Estate CI/CD Audit startup failure has a different cause and is not fixed here. cicd-suite's reusable references @main and @v7.0.1, which violates sha_pinning_required: true.

Evidence this PR works

This PR's own rust-ci run is the test. A startup failure produces zero jobs; a green check job whose steps ran is the pass.

🤖 Generated with Claude Code

https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f

…/rust-toolchain

rust-ci has startup-failed on every push since 0f53008. The workflow file
did not change; this repo's Actions policy admits only GitHub-owned and
verified actions (patterns_allowed is empty), and dtolnay/rust-toolchain
is neither, so the run is refused before any job starts.

The action was also redundant: rust-toolchain.toml already pins the
channel (1.97.1) and the rustfmt/clippy components, which a bare
`rustup toolchain install` reads. The action's `toolchain: stable` input
was being overridden by that file anyway.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 0c7aa0ea-ba87-4965-b3c0-b4673a90b355

📥 Commits

Reviewing files that changed from the base of the PR and between aedfc2f and 6615fcd.

📒 Files selected for processing (1)
  • .github/workflows/rust-ci.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (5)
  • GitHub Check: secret-scan / gitleaks
  • GitHub Check: CodeQL Analysis (rust)
  • GitHub Check: CodeQL Analysis (actions)
  • GitHub Check: check
  • GitHub Check: semgrep-cloud-platform/scan
🧰 Additional context used
🪛 zizmor (1.30.0)
.github/workflows/rust-ci.yml

[warning] 16-20: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)

🔇 Additional comments (1)
.github/workflows/rust-ci.yml (1)

17-26: LGTM!


📝 Summary

Summary by CodeRabbit

  • Chores
    • Updated the Rust CI setup to install the stable toolchain and report the versions used for formatting and lint checks. Existing formatting, linting, test, build and end-to-end checks remain unchanged. This change affects the project’s automated validation process; it does not alter application functionality or introduce user-facing changes.

Walkthrough

The Rust CI workflow replaces a pinned toolchain action with shell commands to install the repository-configured toolchain and print the rustc, cargo fmt, and cargo clippy versions. Later CI steps remain unchanged.

Changes

Rust CI toolchain setup

Layer / File(s) Summary
Install and report toolchain versions
.github/workflows/rust-ci.yml
A shell step replaces the pinned toolchain action. It installs the toolchain configured for the repository and prints compiler, formatter, and linter versions.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 6615f

CI uses the configured Rust toolchain and components. No actionable merge-blocking risk is established.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 6615f

The change does not add workflow permissions or secret references, and toolchain installation remains ahead of all validation steps. No introduced security concern was established. Successful execution and organization-level controls were not independently verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The directly affected scope is tooling installed for the rust-ci check job. The inspected change establishes no additional tenant, service, data-store, or deployment authority.

Security Findings and Attack Paths

  • inferred — A pull request can influence provisioning through its toolchain configuration. However, the workflow already executes repository-controlled tests and e2e scripts, and the change adds no credential scope; this configuration influence alone does not establish a newly privileged attack path.

Trust Boundaries and Controls

  • observed — Toolchain selection authority moves from explicit workflow action inputs to checked-out repository configuration. The current configuration pins an exact channel and required components, while workflow token permissions remain unchanged.

Resilience and Maintainability Implications

  • inferred — The repository-defined transition confines provisioning to the runner and places consumers after successful setup. No new durable cleanup or recovery obligation is visible, although external runner persistence and installation-source policy remain outside the inspected scope.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: replacing the blocked third-party Rust toolchain action with rustup.
Description check ✅ Passed The description is directly related to the changeset. It explains the action-policy failure, the rustup replacement, the unchanged workflow scope, and the validation evidence.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

I’m a rabbit; Rust tools now hop in line,
The workflow installs the toolchain fine.
rustc reports, and fmt joins the show,
Clippy shares its version before tests go.
The later CI steps keep their place,
I nibble a leaf and bound with grace.

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 996b5cd into main Sep 30, 2026
12 checks passed
@hyperpolymath
hyperpolymath deleted the ci/rustup-not-third-party-action branch September 30, 2026 09:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant