From 26d2fe1891d11c9cadb0ffd55ebe127cbcac7051 Mon Sep 17 00:00:00 2001 From: Anthony Lukach Date: Fri, 25 Sep 2026 08:54:12 -0700 Subject: [PATCH] ci: keep Cargo.lock in step with releases and gate CI on --locked release-please bumped every workspace crate's version in Cargo.toml but never touched Cargo.lock, so the lockfile went stale on each release (main carried 0.7.1 entries against a 0.7.2 manifest until the next cargo invocation happened to rewrite it). Nothing caught it because CI ran without --locked. The release PR now also rewrites the lock entries: a TOML extra-file whose JSONPath selects every `[[package]]` without a `source`, which is exactly the set of workspace members (registry and VCS dependencies all carry one). The check job runs `cargo check --locked`, so a stale lockfile fails CI instead of silently regenerating. Co-Authored-By: Claude Fable 5.1 --- .github/workflows/ci.yml | 2 +- CONTRIBUTING.md | 2 ++ release-please-config.json | 5 +++++ 3 files changed, 8 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index cc5c653..35b0964 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -47,7 +47,7 @@ jobs: with: toolchain: stable - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 - - run: cargo check + - run: cargo check --locked check-wasm: name: Cargo Check (WASM) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 8ab17e3..91208ed 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -24,6 +24,8 @@ cargo test make test-integration ``` +`Cargo.lock` is committed and CI runs `cargo check --locked`, so commit lockfile changes alongside any dependency change. The release PR bumps the workspace members' entries in `Cargo.lock` itself (see `release-please-config.json`), so a release never leaves the lockfile stale. + ## Release Process ### Publishable Crates diff --git a/release-please-config.json b/release-please-config.json index a9275d7..bf0c09b 100644 --- a/release-please-config.json +++ b/release-please-config.json @@ -44,6 +44,11 @@ "type": "toml", "path": "Cargo.toml", "jsonpath": "$.workspace.dependencies.multistore-path-mapping.version" + }, + { + "type": "toml", + "path": "Cargo.lock", + "jsonpath": "$.package[?(!@.source)].version" } ] }