Skip to content

fix(ci): codeql-action v4.38.1 -> v4.38.0 SHA pin + dependabot hold #182

fix(ci): codeql-action v4.38.1 -> v4.38.0 SHA pin + dependabot hold

fix(ci): codeql-action v4.38.1 -> v4.38.0 SHA pin + dependabot hold #182

Workflow file for this run

# This workflow is managed by gh actions-lock.

Check failure on line 1 in .github/workflows/rust-ci.yml

View workflow run for this annotation

GitHub Actions / .github/workflows/rust-ci.yml

Invalid workflow file

(Line: 40, Col: 9): 'with' is already defined
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
#
# rust-ci.yml — Cargo build, test, clippy, and fmt for Rust projects.
# Only runs if Cargo.toml exists in the repo root.
name: Rust CI
on:
pull_request:
branches: ['**']
push:
branches: [main, master]
# Estate guardrail: cancel superseded runs so re-pushes don't pile up
# queued runs across the estate. Safe here because this workflow only
# performs read-only checks/lint/test/scan with no publish or mutation.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
check:
name: Cargo check + clippy + fmt
runs-on: ubuntu-latest
if: hashFiles('Cargo.toml') != ''
steps:
- name: Checkout repository
uses: actions/checkout@v7.0.1
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@v1
with:
toolchain: master
with:
components: clippy, rustfmt
- name: Cache cargo registry and build
uses: Swatinem/rust-cache@v2.9.2
- name: Cargo check
run: cargo check --all-targets 2>&1
- name: Cargo fmt
run: cargo fmt --all -- --check
- name: Cargo clippy
run: cargo clippy --all-targets -- -D warnings
# Estate guardrail (warn-only, non-breaking ratchet): surface
# panic-prone patterns (.unwrap() / panic!()) without failing CI.
# `--cap-lints warn` neutralises the `-D warnings` above so this step
# can never break the build, and continue-on-error is a second safety
# net. To be ratcheted toward `-D` per-repo once the estate is clean.
- name: Cargo clippy (panic-gate, warn-only)
continue-on-error: true
run: cargo clippy --all-targets --cap-lints warn -- -W clippy::unwrap_used -W clippy::panic
test:
name: Cargo test
runs-on: ubuntu-latest
needs: check
if: hashFiles('Cargo.toml') != ''
steps:
- name: Checkout repository
uses: actions/checkout@v7.0.1
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@v1
- name: Cache cargo registry and build
uses: Swatinem/rust-cache@v2.9.2
- name: Run tests
run: cargo test --all-targets
- name: Write summary
if: always()
run: |
echo "## Rust CI Results" >> "$GITHUB_STEP_SUMMARY"
echo "" >> "$GITHUB_STEP_SUMMARY"
echo "- **cargo check**: passed" >> "$GITHUB_STEP_SUMMARY"
echo "- **cargo test**: completed" >> "$GITHUB_STEP_SUMMARY"