-
Notifications
You must be signed in to change notification settings - Fork 13
Pin module release builds to Rust 1.96.1 #162
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -467,7 +467,7 @@ jobs: | |
| - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2 | ||
|
|
||
| - name: Build with the declared MSRV | ||
| run: cargo build --all-targets --all-features | ||
| run: cargo +${{ steps.msrv.outputs.version }} build --all-targets --all-features | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Pass the MSRV through the environment before invoking the shell The MSRV output is currently expanded into the [RULE] shell-injection · |
||
|
|
||
| supply-chain: | ||
| name: Supply chain | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,3 @@ | ||
| [toolchain] | ||
| channel = "1.96.1" | ||
| profile = "minimal" | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Install the components required by repository checks A [RULE] missing-toolchain-components · There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Install the components required by repository checks The minimal rustup profile does not install [RULE] missing-toolchain-components · |
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pass the MSRV through a quoted environment variable
steps.msrv.outputs.versionis derived fromCargo.tomlin the checked-out repository and is interpolated directly into a shell command. A crafted value that reaches this output could alter the command executed by the runner. Put the output in an environment variable and invoke Cargo with the quoted variable, for examplecargo +"$MSRV" build ....Additional
critiqueobservationPass the MSRV through the environment before invoking the shell
[RULE] shell-interpolation
steps.msrv.outputs.versionis derived from the repository'sCargo.toml, which is untrusted in pull-request CI, and is interpolated directly intorun. Keep the expression in anenvvalue and invokecargo +"$MSRV" ...so repository-controlled data is not expanded as shell source.[RULE] untrusted-shell-interpolation ·