Files
fips/.github
Johnathan Corgan c7a74a88a0 Pin the nextest and nightly toolchain actions by commit SHA
The three cargo-nextest install steps in ci.yml and the nightly toolchain
step in package-openwrt.yml were the last action references left on
mutable refs. Their owners can move a tag or branch to different code at
any time, and the install-action v2 tag has already moved off the commit
this repository pins for cargo-ndk.

The nextest steps now use that same install-action commit, so there is one
install-action pin to bump rather than two. That lineage declares the
`tool` input required, so each step passes `tool: nextest`; its manifest
installs cargo-nextest 0.9.143, which stays fixed until the pin is bumped
by hand. The toolchain step is pinned to the head of rust-toolchain's
nightly branch and names `toolchain: nightly` explicitly, so a later bump
to a commit whose input has no default still resolves the same channel.
Pinning that action does not pin the toolchain: rustup still resolves
nightly when the step runs.

With every reference pinned, the action pin guard no longer needs its
list of individually allowed mutable refs or the function that matched
against it. Removing both, rather than leaving an empty list, also avoids
expanding an empty array under `set -u`, which bash releases before 4.4
treat as an unbound variable. The comment that justified the exceptions is
replaced by how to pin an action that selects its tool or toolchain from
the ref name: pin the SHA and pass the selection as an explicit `with:`
input. The success message drops "or justified".
2026-10-01 22:40:40 +00:00
..