Replace the floating `stable` channel with the exact current latest stable
(1.96.0, which also matches the crate's rust-version/MSRV) so builds are
reproducible and `clippy -D warnings` can't break from an unrelated toolchain
bump.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Update each action to its current latest release and pin to the full commit
SHA (supply-chain hardening), with the version in a trailing comment:
* actions/checkout v4 -> v7.0.0
* Swatinem/rust-cache v2 -> v2.9.1
* actions/upload-artifact v4 -> v7.0.1
* actions/download-artifact v4 -> v8.0.1
* softprops/action-gh-release v2 -> v3.0.1
* dtolnay/rust-toolchain pinned to master @ 2026-06-20 (no tagged
releases); add explicit `toolchain: stable` since the channel can no
longer be inferred from the @ref once pinned to a SHA.
Verified upload-artifact v7 (zips by default) and download-artifact v8
interoperate, and that every input still exists in the new majors.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* ci.yml: on pull requests to main, runs on windows-latest and macos-latest;
checks formatting, runs clippy (warnings denied), and runs the unit tests
(`cargo test --workspace`).
* release.yml: manual workflow_dispatch (tag + optional prerelease inputs);
builds release binaries for Windows (x86_64) and macOS (aarch64 + x86_64),
then publishes them to GitHub Releases with auto-generated notes.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>