rust-lang / rust-lang/rustfmt

Make sure our CI workflows build with `--locked`

Open
#7,037 8 comments 0 reactions 1 assignee View on GitHub

@jieyouxu is already working on this.

Since Aug 20, 2026.

A-CI A-supply-chain-security C-bug
Dominant language
Rust
Stars
7k
Forks
1.1k
Avg merge
2d 13h
Merged PRs (30d)
24

Description

E.g. double-check that we don't try to just fetch newest-compatible versions; instead, we generally should use the checked-in lockfile.

https://github.com/rust-lang/rustfmt/blob/164f17c60f5728814999c9c08e93facb98094600/.github/workflows/check_diff.yml#L49

(Would like to double-check after reminded by today's https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/)

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.