ci(rust): install the toolchain with rustup, not a blocked third-party action - #41
Conversation
…/rust-toolchain rust-ci has startup-failed on every push since 0f53008. The workflow file did not change; this repo's Actions policy admits only GitHub-owned and verified actions (patterns_allowed is empty), and dtolnay/rust-toolchain is neither, so the run is refused before any job starts. The action was also redundant: rust-toolchain.toml already pins the channel (1.97.1) and the rustfmt/clippy components, which a bare `rustup toolchain install` reads. The action's `toolchain: stable` input was being overridden by that file anyway. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (5)
🧰 Additional context used🪛 zizmor (1.30.0).github/workflows/rust-ci.yml[warning] 16-20: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) 🔇 Additional comments (1)
📝 SummarySummary by CodeRabbit
WalkthroughThe Rust CI workflow replaces a pinned toolchain action with shell commands to install the repository-configured toolchain and print the ChangesRust CI toolchain setup
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to CI uses the configured Rust toolchain and components. No actionable merge-blocking risk is established. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change does not add workflow permissions or secret references, and toolchain installation remains ahead of all validation steps. No introduced security concern was established. Successful execution and organization-level controls were not independently verified. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. I’m a rabbit; Rust tools now hop in line, Comment |
rust-cihas startup-failed on every push tomainsince0f53008(#38). The workflow file itself did not change. This repo's Actions policy isallowed_actions: selectedwithpatterns_allowed: [], so only GitHub-owned and verified-creator actions may run.dtolnay/rust-toolchainis neither, so GitHub refuses the run before any job starts.The action was redundant anyway.
rust-toolchain.tomlalready pinschannel = "1.97.1"plusrustfmtandclippy, and a barerustup toolchain installon the runner reads that file.Scope
Central Estate CI/CD Auditstartup failure has a different cause and is not fixed here.cicd-suite's reusable references@mainand@v7.0.1, which violatessha_pinning_required: true.Evidence this PR works
This PR's own
rust-cirun is the test. A startup failure produces zero jobs; a greencheckjob whose steps ran is the pass.🤖 Generated with Claude Code
https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f