ci: drop ci-env, pin actions to SHAs, and lint workflows - #86
Merged
Merged
Conversation
ci-workflows removed its ci-env composite action (argumentcomputer/ci-workflows#89), so both jobs that checked it out failed at that step. The toolchain action's v2 defaults cover what ci-env set: incremental off, colored output, short backtraces, and warnings denied through cargo's build.warnings instead of RUSTFLAGS. With RUSTFLAGS no longer exported, the .cargo/config.toml codegen flags now apply to the ubuntu-latest jobs as they already did to cuda-compile. Pin every action to a full commit SHA with pinact, replacing the moving `install-action@nextest` alias with the release pin plus `tool: nextest`. Add the ci-workflows lint-workflows step (actionlint, shellcheck, pinact verify, zizmor) to the lints job ahead of the toolchain setup. ci-workflows publishes no tags, so .github/pinact.yaml exempts its commit-pinned actions from version-comment verification. Also set persist-credentials: false on every checkout, pass the cargo-deny Rust version as a step output instead of through GITHUB_ENV, use github.token in the Nix workflow, and raise Dependabot's cooldown from the 3-day default to the 7 days zizmor's dependabot-cooldown audit requires.
samuelburnham
enabled auto-merge (squash)
October 1, 2026 16:57
arthurpaulino
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ci-workflows removed its ci-env composite action (argumentcomputer/ci-workflows#89), so both jobs that checked it out failed at that step. The toolchain action's v2 defaults cover what ci-env set: incremental off, colored output, short backtraces, and warnings denied through cargo's build.warnings instead of RUSTFLAGS. With RUSTFLAGS no longer exported, the .cargo/config.toml codegen flags now apply to the ubuntu-latest jobs as they already did to cuda-compile.
Pin every action to a full commit SHA with pinact, replacing the moving
install-action@nextestalias with the release pin plustool: nextest. Add the ci-workflows lint-workflows step (actionlint, shellcheck, pinact verify, zizmor) to the lints job ahead of the toolchain setup. ci-workflows publishes no tags, so .github/pinact.yaml exempts its commit-pinned actions from version-comment verification.Also set persist-credentials: false on every checkout, pass the cargo-deny Rust version as a step output instead of through GITHUB_ENV, use github.token in the Nix workflow, and raise Dependabot's cooldown from the 3-day default to the 7 days zizmor's dependabot-cooldown audit requires.