Skip to content

chore(deps): bump Swatinem/rust-cache from 2.9.1 to 2.9.2 - #229

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/Swatinem/rust-cache-2.9.2
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/Swatinem/rust-cache-2.9.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor

Bumps Swatinem/rust-cache from 2.9.1 to 2.9.2.

Release notes

Sourced from Swatinem/rust-cache's releases.

v2.9.2

What's Changed

New Contributors

Full Changelog: Swatinem/rust-cache@v2.9.1...v2.9.2

Changelog

Sourced from Swatinem/rust-cache's changelog.

Changelog

2.9.2

  • Fix credentials.toml cleanup
  • Improvements to cleanup, preserving more valid targets
  • Improvements to cargo install handling
  • Correctly sort/dedupe Rust versions

2.9.1

  • Fix regression in hash calculation

2.9.0

  • Update to node24
  • Support running from within a nix shell
  • Consider all installed toolchains for cache key
  • Use case-insensitive comparison to determine exact cache hit

2.8.2

  • Don't overwrite env for cargo-metadata call

2.8.1

  • Set empty CARGO_ENCODED_RUSTFLAGS when retrieving metadata
  • Various dependency updates

2.8.0

  • Add support for warpbuild cache provider
  • Add new cache-workspace-crates feature

2.7.8

  • Include CPU arch in the cache key

2.7.7

  • Also cache cargo install metadata

2.7.6

  • Allow opting out of caching $CARGO_HOME/bin
  • Add runner OS in cache key
  • Adds an option to do lookup-only of the cache

2.7.5

... (truncated)

Commits
  • 6323deb 2.9.2
  • b16e8d7 bump rollup and rebuild
  • 3bf42ac invert target/profile check in cleanup
  • 6e5b278 correctly sort and dedupe Rust versions
  • 5adc05f Bump the actions group across 1 directory with 3 updates (#368)
  • 66b1e95 fix: support Cargo V2 build dir layout (#371)
  • 72d126e Merge pull request #367 from Swatinem/dependabot/npm_and_yarn/dev-patch-2b495...
  • 48968d2 Bump the dev-patch group with 2 updates
  • 9f151ac update dependencies, rebuild
  • 0e24e5d Bump the actions group across 1 directory with 6 updates (#364)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [Swatinem/rust-cache](https://github.com/swatinem/rust-cache) from 2.9.1 to 2.9.2.
- [Release notes](https://github.com/swatinem/rust-cache/releases)
- [Changelog](https://github.com/Swatinem/rust-cache/blob/master/CHANGELOG.md)
- [Commits](Swatinem/rust-cache@v2.9.1...6323deb)

---
updated-dependencies:
- dependency-name: Swatinem/rust-cache
  dependency-version: 2.9.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 14, 2026
@clawsweeper

clawsweeper Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 14, 2026
@clawsweeper

clawsweeper Bot commented Sep 14, 2026

Copy link
Copy Markdown

Codex review: needs maintainer review before merge. Reviewed September 14, 2026, 12:23 PM ET / 16:23 UTC.

ClawSweeper review

What this changes

Updates the Rust build-cache action from v2.9.1 to v2.9.2 in the runtime-install isolation reproduction workflow.

Merge readiness

✅ Ready for maintainer review

Keep open: this workflow still needs the update on main. The focused dependency bump matches the pin already used by regular CI, and no blocking defect was found.

Priority: P3
Reviewed head: d1a9f25e9e81a22740ed4b8d7dfbc9ff80ad4f4b

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A focused, compatible dependency update with verified upstream provenance and no actionable findings.
Proof confidence 🌊 off-meta tidepool Not applicable: Dependabot’s workflow-only update is exempt from contributor runtime proof; supplied CI results are supplemental and do not establish execution of the manually triggered reproduction workflow.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: Dependabot’s workflow-only update is exempt from contributor runtime proof; supplied CI results are supplemental and do not establish execution of the manually triggered reproduction workflow.
Evidence reviewed 6 items Verified introduced change: The pinned base-to-head diff changes only one action reference; workflow triggers, read-only contents permission, credential persistence, and reproduction commands remain unchanged.
Update remains necessary: The fetched main revision retains v2.9.1 in this workflow. Regular CI already uses v2.9.2 at four call sites, but that does not update this separate workflow.
Release boundary: The reproduction workflow does not exist in the supplied latest release, v0.2.46; there is no released implementation of this exact workflow update.
Findings None None.
Security None None.

How this fits together

OCM’s reproduction workflow builds and tests Rust code on an isolated GitHub runner, then uploads diagnostic evidence. The cache action restores build dependencies before those checks and saves reusable artifacts afterward.

flowchart LR
  A[Manual or branch trigger] --> B[Isolated Ubuntu runner]
  B --> C[Restore Rust cache]
  C --> D[Build and isolation checks]
  D --> E[Upload reproduction evidence]
  D --> F[Save reusable cache]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

None.

Technical review

Best possible solution:

Keep the reproduction workflow aligned with regular CI’s immutable v2.9.2 action pin.

Do we have a high-confidence way to reproduce the issue?

Not applicable: this is a dependency maintenance update, not a reported OCM bug; no builds or tests were executed during the read-only review.

Is this the best way to solve the issue?

Yes: updating the existing immutable reference is the narrowest solution and matches regular CI without changing workflow permissions or configuration.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 3cb61a7d1751.

Labels

Label changes:

  • add P3: Routine maintenance of one CI cache-action pin with no identified user-facing regression.
  • add rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • add status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: Dependabot’s workflow-only update is exempt from contributor runtime proof; supplied CI results are supplemental and do not establish execution of the manually triggered reproduction workflow.

Label justifications:

  • P3: Routine maintenance of one CI cache-action pin with no identified user-facing regression.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: Dependabot’s workflow-only update is exempt from contributor runtime proof; supplied CI results are supplemental and do not establish execution of the manually triggered reproduction workflow.

Evidence

What I checked:

  • Verified introduced change: The pinned base-to-head diff changes only one action reference; workflow triggers, read-only contents permission, credential persistence, and reproduction commands remain unchanged. (.github/workflows/reproduce-ocm-98.yml:28, d1a9f25e9e81)
  • Update remains necessary: The fetched main revision retains v2.9.1 in this workflow. Regular CI already uses v2.9.2 at four call sites, but that does not update this separate workflow. (.github/workflows/reproduce-ocm-98.yml:28, 3cb61a7d1751)
  • Release boundary: The reproduction workflow does not exist in the supplied latest release, v0.2.46; there is no released implementation of this exact workflow update. (.github/workflows/reproduce-ocm-98.yml, fc9f330476d3)
  • Verified dependency provenance: The workflow directly executes this dependency. GitHub identifies its repository as Swatinem/rust-cache, and the verified annotated v2.9.2 tag resolves to the exact proposed commit. (6323deb102c3)
  • Action compatibility and security: Inspected upstream action metadata, package and provider changes, cleanup changes, save implementation, and distributed entrypoint names. Node 24 and the default GitHub cache provider remain supported; the removed BuildJet option is unused here. The new restore/save entrypoints exist, and credential cleanup corrects the credentials.toml path. (action.yml:71, 6323deb102c3)
  • Feature-history routing: GitHub file history and the commit patch associate this workflow with merged fix: isolate runtime install lifecycle state #131, authored by MertBasar0; its commit records shakkernerd as reviewer and co-author. Local follow-history inspection encountered an unavailable promisor object, so GitHub commit records supplied the history evidence. (.github/workflows/reproduce-ocm-98.yml:10, 3cb61a7d1751)

Likely related people:

  • Mert Başar: Raw commit 3cb61a7 adds .github/workflows/reproduce-ocm-98.yml:10 relative to its recorded parents. This identifies author metadata, not feature responsibility or a PR merger. (role: source-line author; confidence: high; commits: 3cb61a7d1751; files: .github/workflows/reproduce-ocm-98.yml)
  • shakkernerd: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@dependabot @github

dependabot Bot commented on behalf of github Sep 15, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #236.

@dependabot dependabot Bot closed this Sep 15, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/Swatinem/rust-cache-2.9.2 branch September 15, 2026 23:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants