From e4e59e0d228c4537fca25b0d0c6fc8440e83a89c Mon Sep 17 00:00:00 2001 From: Kenneth Pernyer Date: Thu, 2 Jul 2026 10:57:41 +0200 Subject: [PATCH] =?UTF-8?q?fix(ci):=20run=20cargo-deny=20in=20runner=20env?= =?UTF-8?q?=20=E2=80=94=20docker=20action=20can't=20see=20toolchain=20or?= =?UTF-8?q?=20siblings?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Same failure shape as prism-analytics: EmbarkStudios/cargo-deny-action@v2 can't install the pinned 1.96.0 musl toolchain and doesn't see sibling checkouts, so cargo metadata dies on converge-core. Mirror the blocking audit job's runner-env pattern. Co-Authored-By: Claude Fable 5 --- .github/workflows/stability.yml | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/.github/workflows/stability.yml b/.github/workflows/stability.yml index 70f32be..2969b75 100644 --- a/.github/workflows/stability.yml +++ b/.github/workflows/stability.yml @@ -115,4 +115,16 @@ jobs: - uses: actions/checkout@v6 - name: Checkout Reflective sibling dependencies run: bash scripts/ci/checkout-reflective-siblings.sh - - uses: EmbarkStudios/cargo-deny-action@v2 + # Not EmbarkStudios/cargo-deny-action: its docker container can't + # install the repo's pinned musl toolchain and doesn't see the + # sibling checkouts, so `cargo metadata` fails on converge-core. + # Run cargo-deny in the runner env like the audit job above. + - uses: dtolnay/rust-toolchain@stable + with: + toolchain: ${{ env.RUST_VERSION }} + - uses: Swatinem/rust-cache@v2 + - uses: taiki-e/install-action@v2 + with: + tool: cargo-deny + - name: Run cargo-deny + run: cargo deny check