Skip to content

fix: replace archived actions-rs/toolchain with dtolnay/rust-toolchain (supply chain hardening)#9035

Open
XananasX7 wants to merge 1 commit intogoogle:masterfrom
XananasX7:patch-1
Open

fix: replace archived actions-rs/toolchain with dtolnay/rust-toolchain (supply chain hardening)#9035
XananasX7 wants to merge 1 commit intogoogle:masterfrom
XananasX7:patch-1

Conversation

@XananasX7
Copy link
Copy Markdown

Replaces the archived actions-rs/toolchain@v1 action (actions-rs org was abandoned in 2023, mutable tag) with the actively-maintained dtolnay/rust-toolchain@stable in the publish-crates job.

This job has simultaneous access to CARGO_TOKEN, NPM_TOKEN, TWINE_TOKEN, NUGET_API_KEY, OSSRH_USER_V2, OSSRH_TOKEN_V2, MAVEN_GPG_PRIVATE_KEY, and MAVEN_GPG_PASSPHRASE. A compromised action tag could exfiltrate all 8 secrets in a single workflow run.

@XananasX7 XananasX7 requested a review from dbaileychess as a code owner April 9, 2026 20:04
@github-actions github-actions bot added the CI Continuous Integration label Apr 9, 2026
@XananasX7
Copy link
Copy Markdown
Author

@google-cla-bot check

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI Continuous Integration

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant