Skip to content

CI: use native Cargo dependency cooldown feature - #2552

Merged
marxin merged 3 commits into
wild-linker:mainfrom
marxin:dependency-cooldown
Sep 20, 2026
Merged

marxin merged 3 commits into
wild-linker:mainfrom
marxin:dependency-cooldown

Conversation

@marxin

@marxin marxin commented Sep 19, 2026 •

Copy link
Copy Markdown
Collaborator

With the increasing number of supply chain attacks (1), Cargo introduced a native cooldown mechanism that will be stabilized in 1.100 (if I'm not mistaken): rust-lang/cargo#17335. So far available on +nightly Cargo version.

The check can properly detect if a version from Cargo.toml does not fulfill the cooldown period, but there's one drawback connected to Cargo.lock file dependencies - these are ignored and only a warning is reported. So until the feature is stabilized, one must use nightly compiler for updating.

Sample output if accidentally updated to latest:

❯ cargo +nightly update
    Updating crates.io index
     Locking 6 packages to highest compatible versions as of 3 days ago
 Downgrading cc v1.4.7 -> v1.4.6 (available: v1.4.7, published 19 hours ago)
 Downgrading cfg-if v1.0.5 -> v1.0.4 (available: v1.0.5, published 3 days ago)
 Downgrading find-msvc-tools v0.1.13 -> v0.1.12 (available: v0.1.13, published 19 hours ago)
 Downgrading rustix v1.1.5 -> v1.1.4 (available: v1.1.5, published 2 days ago)
 Downgrading syn v3.0.6 -> v3.0.5 (available: v3.0.6, published 2 days ago)
 Downgrading unicode-ident v1.0.26 -> v1.0.24 (available: v1.0.26, published 2 days ago)
note: pass `--verbose` to see 1 unchanged dependencies behind latest

If sticking to a fresh release in Cargo.toml:

❯ cargo +nightly update
    Updating crates.io index
error: failed to select a version for the requirement `cc = "^1.4.7"`
  version 1.4.7 is too new (published 19 hours ago, minimum age 3 days)
location searched: crates.io index

And the linked blog post is also pretty nice reading: https://cooldowns.dev/

Footnotes

  1. https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/ ↩

@marxin
marxin force-pushed the dependency-cooldown branch from 3d11cab to 3acfdeb Compare September 19, 2026 08:24

@davidlattimore davidlattimore left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! I'd been thinking it'd be good if we could take advantage of that feature somehow

Comment thread .cargo/config.toml.publish-age
Comment thread .github/workflows/ci.yml Outdated
@davidlattimore

davidlattimore commented Sep 20, 2026 •

Copy link
Copy Markdown
Member

I was just wondering about what dependabot will do and found that it has a 3 day cooldown by default - introduced relatively recently. So I guess this CI job will mostly force us to slow down if people do a manual cargo update.

edit: I see this is mentioned in the article you linked, so probably isn't news to you :)

@marxin

marxin commented Sep 20, 2026

Copy link
Copy Markdown
Collaborator Author

Yes, I know it aligns nicely with Dependabot ;)

@marxin
marxin merged commit 71cf142 into wild-linker:main Sep 20, 2026
25 checks passed
@marxin
marxin deleted the dependency-cooldown branch September 20, 2026 14:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants