mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
The three cargo-nextest install steps in ci.yml and the nightly toolchain step in package-openwrt.yml were the last action references left on mutable refs. Their owners can move a tag or branch to different code at any time, and the install-action v2 tag has already moved off the commit this repository pins for cargo-ndk. The nextest steps now use that same install-action commit, so there is one install-action pin to bump rather than two. That lineage declares the `tool` input required, so each step passes `tool: nextest`; its manifest installs cargo-nextest 0.9.143, which stays fixed until the pin is bumped by hand. The toolchain step is pinned to the head of rust-toolchain's nightly branch and names `toolchain: nightly` explicitly, so a later bump to a commit whose input has no default still resolves the same channel. Pinning that action does not pin the toolchain: rustup still resolves nightly when the step runs. With every reference pinned, the action pin guard no longer needs its list of individually allowed mutable refs or the function that matched against it. Removing both, rather than leaving an empty list, also avoids expanding an empty array under `set -u`, which bash releases before 4.4 treat as an unbound variable. The comment that justified the exceptions is replaced by how to pin an action that selects its tool or toolchain from the ref name: pin the SHA and pass the selection as an explicit `with:` input. The success message drops "or justified".