Skip to content

ci: drop ci-env, pin actions to SHAs, and lint workflows - #86

Merged
samuelburnham merged 1 commit into
mainfrom
ci/drop-ci-env
Oct 1, 2026
Merged

samuelburnham merged 1 commit into
mainfrom
ci/drop-ci-env

Conversation

@samuelburnham

Copy link
Copy Markdown
Member

ci-workflows removed its ci-env composite action (argumentcomputer/ci-workflows#89), so both jobs that checked it out failed at that step. The toolchain action's v2 defaults cover what ci-env set: incremental off, colored output, short backtraces, and warnings denied through cargo's build.warnings instead of RUSTFLAGS. With RUSTFLAGS no longer exported, the .cargo/config.toml codegen flags now apply to the ubuntu-latest jobs as they already did to cuda-compile.

Pin every action to a full commit SHA with pinact, replacing the moving install-action@nextest alias with the release pin plus tool: nextest. Add the ci-workflows lint-workflows step (actionlint, shellcheck, pinact verify, zizmor) to the lints job ahead of the toolchain setup. ci-workflows publishes no tags, so .github/pinact.yaml exempts its commit-pinned actions from version-comment verification.

Also set persist-credentials: false on every checkout, pass the cargo-deny Rust version as a step output instead of through GITHUB_ENV, use github.token in the Nix workflow, and raise Dependabot's cooldown from the 3-day default to the 7 days zizmor's dependabot-cooldown audit requires.

ci-workflows removed its ci-env composite action (argumentcomputer/ci-workflows#89),
so both jobs that checked it out failed at that step. The toolchain action's v2
defaults cover what ci-env set: incremental off, colored output, short
backtraces, and warnings denied through cargo's build.warnings instead of
RUSTFLAGS. With RUSTFLAGS no longer exported, the .cargo/config.toml codegen
flags now apply to the ubuntu-latest jobs as they already did to cuda-compile.

Pin every action to a full commit SHA with pinact, replacing the moving
`install-action@nextest` alias with the release pin plus `tool: nextest`.
Add the ci-workflows lint-workflows step (actionlint, shellcheck, pinact
verify, zizmor) to the lints job ahead of the toolchain setup. ci-workflows
publishes no tags, so .github/pinact.yaml exempts its commit-pinned actions
from version-comment verification.

Also set persist-credentials: false on every checkout, pass the cargo-deny
Rust version as a step output instead of through GITHUB_ENV, use
github.token in the Nix workflow, and raise Dependabot's cooldown from the
3-day default to the 7 days zizmor's dependabot-cooldown audit requires.
@samuelburnham
samuelburnham enabled auto-merge (squash) October 1, 2026 16:57
@samuelburnham
samuelburnham merged commit 9b4eaa2 into main Oct 1, 2026
8 checks passed
@samuelburnham
samuelburnham deleted the ci/drop-ci-env branch October 1, 2026 18:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants