ci: pin public repo to hosted runners; slim rust builds - #3056
Merged
Merged
Conversation
This repository is public, so routing jobs through vars.GH_RUNNER risks a fork PR executing arbitrary contributor code on the self-hosted fleet, and persisting there to poison later trusted jobs. Standard GitHub-hosted runners are free and unlimited on public repos, so there is no cost reason to take that risk.
goastler
force-pushed
the
ci/rust-build-slimming
branch
from
August 13, 2026 16:20
1c1a52c to
13175a5
Compare
…pendency debuginfo opt-out
… dependency debuginfo opt-out
goastler
marked this pull request as ready for review
August 19, 2026 15:38
# Conflicts: # packages/native-ja4/Cargo.toml # packages/native-merkle/Cargo.toml
publish_release and create_release_pr both run npm run build, which compiles the native-ja4 and native-merkle napi crates, so they want the same cargo settings as the test and lint workflows.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two CI changes.
1. Pin this repo to GitHub-hosted runners
Replaces the
vars.GH_RUNNERindirection with a hardcodedruns-on: ubuntu-latestin all 14 workflows that used it, and drops the variable entirely from this repo. Each site carries a comment explaining why, matching the precedent already inandroid-webview.yml.Why
vars.GH_RUNNERmeans a fork PR can land on the self-hosted fleet, executing arbitrary contributor code on hardware we own. Worse than the immediate execution: a self-hosted runner is persistent, so an attacker can leave something behind — a poisoned cargo/npm cache, a modified toolchain, cron — that later runs inside trusted jobs. That converts a drive-by fork PR into a foothold in the release pipeline. GitHub's own guidance is to use self-hosted runners with private repositories only.The one
macos-15job was already hardcoded and is unaffected.Note for review: the self-hosted capacity labels encoded a per-job size (
2c/4g/20d…4c/8g/40d). Hardcoding toubuntu-latestgives every job 4 cores / 16 GB, which is at or above what each job asked for on CPU and RAM, but the largest jobs previously requested 40 GB of disk against ~14 GB free on a standard hosted runner. If any of those hit disk pressure, thefree_disk_space_*composite actions are the lever, not a larger runner.2. Slim Rust builds in CI
CARGO_INCREMENTAL=0— incremental artifacts are useless in CI (cold target dir each run) and inflate cache size.CARGO_PROFILE_DEV_DEBUG=line-tables-only— keeps backtraces useful without full debug info.Companion PRs: https://github.com/prosopo/captcha-private/pull/4152, https://github.com/prosopo/Protect/pull/474, prosopo/github_actions#7
Ref: https://docs.github.com/en/billing/reference/actions-runner-pricing