Make sure our CI workflows build with `--locked`
Open
@jieyouxu is already working on this.
Since Aug 20, 2026.
A-CI
A-supply-chain-security
C-bug
- Dominant language
- Rust
- Stars
- 7k
- Forks
- 1.1k
- Avg merge
- 2d 13h
- Merged PRs (30d)
- 24
Description
E.g. double-check that we don't try to just fetch newest-compatible versions; instead, we generally should use the checked-in lockfile.
(Would like to double-check after reminded by today's https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/)
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.