Skip to content

build: commit Cargo.lock and build with --locked - #18

Merged
MotherSphere merged 1 commit into
mainfrom
build/commit-cargo-lock
Oct 8, 2026
Merged

MotherSphere merged 1 commit into
mainfrom
build/commit-cargo-lock

Conversation

@MotherSphere

Copy link
Copy Markdown
Member

Spotter ignored its Cargo.lock, so every CI run and every release resolved dependencies afresh: a release could not be rebuilt from its tag, and a new upstream version could change a published binary without any commit. Cargo recommends committing the lockfile for applications, and SignPath expects builds to be reproducible from source.

  • Cargo.lock is no longer ignored and is committed.
  • ci.yml (build, test) and release.yml (release build) pass --locked, so a stale lockfile fails CI instead of being silently updated. Dependabot keeps it current.

Checked locally: cargo test --locked passes (146 tests).

Spotter is an application, and without a lockfile every CI run and every
release resolved its dependencies afresh, so a release could not be rebuilt
from its tag and a new upstream version could change a published binary
without any commit. CI and the release legs now build with --locked.
@MotherSphere
MotherSphere merged commit 3823cb1 into main Oct 8, 2026
3 checks passed
@MotherSphere
MotherSphere deleted the build/commit-cargo-lock branch October 8, 2026 13:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant