From b448f0e33a93c037e8aa77325f17d517f2bfd4d6 Mon Sep 17 00:00:00 2001 From: samuelburnham <45365069+samuelburnham@users.noreply.github.com> Date: Thu, 1 Oct 2026 16:13:24 -0400 Subject: [PATCH] ci: update the Rust toolchain weekly A weekly run of ci-workflows' rust-version action moves rust-toolchain.toml to the latest stable release, rewrites the fenix sha256 in flake.nix and updates the fenix and crane inputs in flake.lock, then opens a PR on update/rust-. The PR is opened with GITHUB_TOKEN, so a maintainer closes and reopens it to run CI. --- .github/workflows/update-rust.yml | 36 +++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) create mode 100644 .github/workflows/update-rust.yml diff --git a/.github/workflows/update-rust.yml b/.github/workflows/update-rust.yml new file mode 100644 index 000000000..f865c2160 --- /dev/null +++ b/.github/workflows/update-rust.yml @@ -0,0 +1,36 @@ +name: Update Rust toolchain + +on: + schedule: + # Weekly on Monday at midnight + - cron: "0 0 * * 1" + timezone: America/New_York + workflow_dispatch: + +permissions: + contents: write + pull-requests: write + +jobs: + update: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + # `update-flake` below rewrites the fenix hash and runs `nix flake update` + - uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1 + with: + github_access_token: ${{ github.token }} + + # Moves the root `rust-toolchain.toml` to the latest stable release, + # with the fenix `sha256` and the fenix and crane inputs in `flake.nix`, + # and opens a PR on `update/rust-`. The zisk and sp1 + # sub-workspaces pin their own toolchains and are left alone. The PR is + # opened with `GITHUB_TOKEN`, so a maintainer closes and reopens it to + # run CI. + - uses: argumentcomputer/ci-workflows/.github/actions/rust-version@main + with: + update-flake: 'true' + pr: 'true'