Pin the nextest and nightly toolchain actions by commit SHA

The three cargo-nextest install steps in ci.yml and the nightly toolchain
step in package-openwrt.yml were the last action references left on
mutable refs. Their owners can move a tag or branch to different code at
any time, and the install-action v2 tag has already moved off the commit
this repository pins for cargo-ndk.

The nextest steps now use that same install-action commit, so there is one
install-action pin to bump rather than two. That lineage declares the
`tool` input required, so each step passes `tool: nextest`; its manifest
installs cargo-nextest 0.9.143, which stays fixed until the pin is bumped
by hand. The toolchain step is pinned to the head of rust-toolchain's
nightly branch and names `toolchain: nightly` explicitly, so a later bump
to a commit whose input has no default still resolves the same channel.
Pinning that action does not pin the toolchain: rustup still resolves
nightly when the step runs.

With every reference pinned, the action pin guard no longer needs its
list of individually allowed mutable refs or the function that matched
against it. Removing both, rather than leaving an empty list, also avoids
expanding an empty array under `set -u`, which bash releases before 4.4
treat as an unbound variable. The comment that justified the exceptions is
replaced by how to pin an action that selects its tool or toolchain from
the ref name: pin the SHA and pass the selection as an explicit `with:`
input. The success message drops "or justified".
This commit is contained in:
Johnathan Corgan
2026-10-01 22:40:40 +00:00
parent a37c62898c
commit c7a74a88a0
3 changed files with 20 additions and 30 deletions
+9 -3
View File
@@ -334,7 +334,9 @@ jobs:
${{ runner.os }}-cargo-
- name: Install cargo-nextest
uses: taiki-e/install-action@nextest
uses: taiki-e/install-action@fcf5432d9f50d67e37ee6e29bdb7a224ff67b4a7 # v2
with:
tool: nextest
# The cache restores target/, including the previous run's report. Remove
# it so the flaky-test check below reads only this run's, and reports a
@@ -418,7 +420,9 @@ jobs:
${{ runner.os }}-cargo-
- name: Install cargo-nextest
uses: taiki-e/install-action@nextest
uses: taiki-e/install-action@fcf5432d9f50d67e37ee6e29bdb7a224ff67b4a7 # v2
with:
tool: nextest
# The cache restores target/, including the previous run's report. Remove
# it so the flaky-test check below reads only this run's, and reports a
@@ -467,7 +471,9 @@ jobs:
${{ runner.os }}-cargo-
- name: Install cargo-nextest
uses: taiki-e/install-action@nextest
uses: taiki-e/install-action@fcf5432d9f50d67e37ee6e29bdb7a224ff67b4a7 # v2
with:
tool: nextest
# The cache restores target/, including the previous run's report. Remove
# it so the flaky-test check below reads only this run's, and reports a
+2 -1
View File
@@ -120,8 +120,9 @@ jobs:
- name: Install Rust toolchain (nightly, Tier 3)
if: matrix.rust_channel == 'nightly'
uses: dtolnay/rust-toolchain@nightly
uses: dtolnay/rust-toolchain@be39649afda95dbf70f87cce95f68b8d5797b296 # nightly
with:
toolchain: nightly
components: rust-src
- name: Cache Cargo registry + build
+9 -26
View File
@@ -14,8 +14,7 @@
#
# What counts as a violation: any `uses:` reference that is not
# * `owner/repo@<40 hex> # <tag>` — the required form, comment mandatory; or
# * a local action, `./path` or `docker://...`; or
# * one of the individually justified references listed below.
# * a local action, `./path` or `docker://...`.
#
# WHAT THIS GUARD DOES NOT COVER, so a green run is not read as "the workflows
# fetch nothing unverified":
@@ -43,19 +42,13 @@ REPO_ROOT="$SCRIPT_DIR/.."
# it cannot describe, and a pin nobody can read is a pin nobody updates.
PINNED_RE='^[^@]+@[0-9a-f]{40} +#.*$'
# Individually justified unpinned references. Each entry is the exact ref text.
#
# Both of these actions read the tool they install from the ref name itself
# (`github.action_ref`), so replacing the ref with a SHA hands them a 40-hex
# string where a toolchain or tool name belongs and the step fails outright.
# They are not pinnable without also moving the selection into `with:`, which
# changes which toolchain resolves, and that is a separate decision from
# pinning. Note what stays exposed: both remain repointable by their upstream
# owners.
ALLOWED_REFS=(
'dtolnay/rust-toolchain@nightly'
'taiki-e/install-action@nextest'
)
# There are no exceptions. Some actions select what they install from the ref
# they are called at: a per-tool `taiki-e/install-action` tag, or a
# `dtolnay/rust-toolchain` channel branch, sets the selection input's default
# in that ref's action.yml. Pin such an action by SHA and pass the selection as
# an explicit `with:` input (`tool:`, `toolchain:`). That form works at a SHA
# from any of the action's refs; a bare SHA does not, because their `v2` and
# `master` trees declare the input required with no default.
if ! command -v git >/dev/null 2>&1; then
echo "check-action-pins: git not available, cannot sweep" >&2
@@ -83,15 +76,6 @@ if [[ ${#files[@]} -eq 0 ]]; then
exit 2
fi
# True when this ref is one of the justified references above.
allowed_ref() {
local ref="$1" entry
for entry in "${ALLOWED_REFS[@]}"; do
[[ "$ref" == "$entry" ]] && return 0
done
return 1
}
violations=0
checked=0
@@ -117,7 +101,6 @@ for f in "${files[@]}"; do
[[ "$ref" == ./* ]] && continue
[[ "$ref" == docker://* ]] && continue
[[ "$ref" =~ $PINNED_RE ]] && continue
allowed_ref "$ref" && continue
echo "$f:$n: $ref"
violations=$((violations + 1))
@@ -141,5 +124,5 @@ if [[ $violations -gt 0 ]]; then
exit 1
fi
echo "check-action-pins: all $checked action reference(s) pinned or justified"
echo "check-action-pins: all $checked action reference(s) pinned"
exit 0