From b44a8f5e9c5062b53a45f91b308fee2bb92374c0 Mon Sep 17 00:00:00 2001 From: samuelburnham <45365069+samuelburnham@users.noreply.github.com> Date: Thu, 1 Oct 2026 16:13:43 -0400 Subject: [PATCH] ci: update the Rust toolchain weekly; track ci-workflows actions from main A weekly run of ci-workflows' rust-version action moves rust-toolchain.toml to the latest stable release, rewrites the fenix sha256 in flake.nix and updates the fenix and crane inputs in flake.lock, then opens a PR on update/rust-. nixpkgs follows fenix here, so it moves in the same PR. The PR is opened with GITHUB_TOKEN, so a maintainer closes and reopens it to run CI. The ci-workflows actions are consumed from `main` as a branch ref, as in the other repositories, instead of a commit pinned by hand: a pinact rule and a zizmor ref-pin policy allow it. ci-workflows publishes no tags, so a version comment cannot be verified either way. --- .github/pinact.yaml | 13 ++++++------ .github/workflows/ci.yml | 2 +- .github/workflows/update-rust.yml | 35 +++++++++++++++++++++++++++++++ .github/zizmor.yml | 7 +++++++ 4 files changed, 49 insertions(+), 8 deletions(-) create mode 100644 .github/workflows/update-rust.yml create mode 100644 .github/zizmor.yml diff --git a/.github/pinact.yaml b/.github/pinact.yaml index 085b6bd..ffc05eb 100644 --- a/.github/pinact.yaml +++ b/.github/pinact.yaml @@ -1,8 +1,7 @@ -# yaml-language-server: $schema=https://raw.githubusercontent.com/suzuki-shunsuke/pinact/main/json-schema/pinact.json version: 3 - -ignore_actions: - # ci-workflows publishes no tags, so its actions are pinned to a commit of - # `main` and carry no release comment for pinact to verify. - - name: argumentcomputer/ci-workflows/.* - ref: "[0-9a-f]{40}" +rules: + # Branch refs that must keep tracking their branch: there is no stable tag + # to pin to. The shared ci-workflows actions are consumed from `main`. + - ignore: true + conditions: + - expr: ActionName matches "^argumentcomputer/ci-workflows/" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index d580a80..cbd10d4 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -40,7 +40,7 @@ jobs: # actionlint, shellcheck, pinact and zizmor over this repo's workflows. # Runs before the toolchain setup so a workflow problem fails fast. - name: Lint workflows - uses: argumentcomputer/ci-workflows/.github/actions/lint-workflows@a3a7b1b8f081503e6bf26341a3c5f759df96497a # main + uses: argumentcomputer/ci-workflows/.github/actions/lint-workflows@main - uses: actions-rust-lang/setup-rust-toolchain@ecabd13d1c56bd1345c230e542e9144811ad706f # v2.0.0 - name: Check Rustfmt code style run: cargo fmt --all --check diff --git a/.github/workflows/update-rust.yml b/.github/workflows/update-rust.yml new file mode 100644 index 0000000..4ee925b --- /dev/null +++ b/.github/workflows/update-rust.yml @@ -0,0 +1,35 @@ +name: Update Rust toolchain + +on: + schedule: + # Weekly on Monday at midnight + - cron: "0 0 * * 1" + timezone: America/New_York + workflow_dispatch: + +permissions: + contents: write + pull-requests: write + +jobs: + update: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + # `update-flake` below rewrites the fenix hash and runs `nix flake update` + - uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1 + with: + github_access_token: ${{ github.token }} + + # Moves `rust-toolchain.toml` to the latest stable release, with the + # fenix `sha256` and the fenix and crane inputs in `flake.nix`, and + # opens a PR on `update/rust-`. nixpkgs follows fenix here, so + # it moves in the same PR. The PR is opened with `GITHUB_TOKEN`, so a + # maintainer closes and reopens it to run CI. + - uses: argumentcomputer/ci-workflows/.github/actions/rust-version@main + with: + update-flake: 'true' + pr: 'true' diff --git a/.github/zizmor.yml b/.github/zizmor.yml new file mode 100644 index 0000000..137c4f6 --- /dev/null +++ b/.github/zizmor.yml @@ -0,0 +1,7 @@ +rules: + unpinned-uses: + config: + policies: + # Branch-tracking ref allowed by .github/pinact.yaml + "argumentcomputer/ci-workflows/*": ref-pin + "*": hash-pin