From decbd1c23f49683a614762b561df112601c94fcf Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 25 Sep 2026 22:04:24 +0000 Subject: [PATCH 1/5] fix: repair unparseable JSON, duplicate Cargo dep, and broken CodeQL matrix - praxis/SymbolicEngine/graphql/package.json: drop trailing comma (invalid JSON) - journal-theme/.github/renovate.json: drop trailing comma (invalid JSON) - journal-theme/Cargo.toml: merge duplicate [dependencies.web-sys] into one entry (union of features) - sinople-theme/.github/workflows/codeql.yml: fix broken build-mode matrix Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- journal-theme/.github/renovate.json | 2 +- journal-theme/Cargo.toml | 10 ++-------- praxis/SymbolicEngine/graphql/package.json | 2 +- sinople-theme/.github/workflows/codeql.yml | 2 +- 4 files changed, 5 insertions(+), 11 deletions(-) diff --git a/journal-theme/.github/renovate.json b/journal-theme/.github/renovate.json index b4047cc..10df832 100644 --- a/journal-theme/.github/renovate.json +++ b/journal-theme/.github/renovate.json @@ -62,7 +62,7 @@ ], "matchPackagePatterns": [ "^eslint-", - "^stylelint-", + "^stylelint-" ] }, { diff --git a/journal-theme/Cargo.toml b/journal-theme/Cargo.toml index 4b6dca5..b116068 100644 --- a/journal-theme/Cargo.toml +++ b/journal-theme/Cargo.toml @@ -23,20 +23,14 @@ web-sys = { version = "0.3", features = [ "Window", "CryptoKey", "SubtleCrypto", + "Performance", + "PerformanceObserver", ] } js-sys = "0.3" getrandom = { version = "0.2", features = ["js"] } capnp = "0.19" capnp-rpc = "0.19" -[dependencies.web-sys] -version = "0.3" -features = [ - "console", - "Performance", - "PerformanceObserver", -] - [profile.release] opt-level = "z" lto = true diff --git a/praxis/SymbolicEngine/graphql/package.json b/praxis/SymbolicEngine/graphql/package.json index 939bc18..cb9825a 100644 --- a/praxis/SymbolicEngine/graphql/package.json +++ b/praxis/SymbolicEngine/graphql/package.json @@ -41,7 +41,7 @@ "devDependencies": { "@graphql-codegen/cli": "^5.0.0", "@graphql-inspector/cli": "^5.0.2", - "bun-types": "latest", + "bun-types": "latest" }, "keywords": [ "wp-praxis", diff --git a/sinople-theme/.github/workflows/codeql.yml b/sinople-theme/.github/workflows/codeql.yml index fdb5ee6..7d786b2 100644 --- a/sinople-theme/.github/workflows/codeql.yml +++ b/sinople-theme/.github/workflows/codeql.yml @@ -41,7 +41,7 @@ jobs: fail-fast: false matrix: include: - build-mode: none + - language: javascript-typescript build-mode: none - language: rust build-mode: none From e4703fffb2673b73ce09096095008f7ee7c51682 Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 25 Sep 2026 22:04:24 +0000 Subject: [PATCH 2/5] fix: unblock main-branch CI failures (rust-secrets, governance, actions.lock) - wharf-core crypto.rs: scanner-allow pragma for deliberate ECDH scalar bytes (the sole rust-secrets finding; contents:read is the only scanner requirement) - secret-scanner.yml: replace stale comment claiming pull-requests:write + actions:read are required (they are not) - governance.yml: pin governance-reusable to 28f7a2cb (fixes update-actions-lock 127) and pass through HYPATIA_SCAN_PAT (fixes Allowlist Preflight policy fetch) - actions.lock: haskell-actions/setup drift -> v2.12.1 (peels to 0f8e8c99) Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- .github/workflows/actions.lock | 8 ++++---- .github/workflows/governance.yml | 6 +++++- .github/workflows/secret-scanner.yml | 8 +++++--- project-wharf/crates/wharf-core/src/crypto.rs | 3 ++- 4 files changed, 16 insertions(+), 9 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index e6b46dc..41e8529 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -11,7 +11,7 @@ workflows: - 'actions/configure-pages@v6.0.0' - 'actions/deploy-pages@v5.0.1' - 'actions/upload-pages-artifact@v5.0.0' - - 'haskell-actions/setup@v2.12.0' + - 'haskell-actions/setup@v2.12.1' '.github/workflows/governance.yml': [] '.github/workflows/hypatia-scan.yml': [] '.github/workflows/instant-sync.yml': @@ -60,9 +60,9 @@ dependencies: repo_id: 496012378 uses: - 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f' - 'haskell-actions/setup@v2.12.0': - ref: 'v2.12.0' - commit: 'sha1-6037f33647c3f17758a2356c80fc4a53d7e0685d' + 'haskell-actions/setup@v2.12.1': + ref: 'v2.12.1' + commit: 'sha1-0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d' owner_id: 75048950 repo_id: 623796603 'hyperpolymath/smtp-notify-action@v0.3.0': diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index d2e2735..e63a8ee 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -16,4 +16,8 @@ permissions: jobs: governance: - uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a + uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@28f7a2cba34c51ebccbc4e99acd4cb7cbe07c71a + secrets: + # Optional credentialed live-policy audit ("Live Actions policy" + # advisory job). Absent secret => advisory notice, not a red run. + HYPATIA_SCAN_PAT: ${{ secrets.HYPATIA_SCAN_PAT }} diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index fd0e978..f3dd0e3 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -14,9 +14,11 @@ permissions: contents: read jobs: scan: - # The reusable's gitleaks job requests pull-requests: write (PR summary - # comment) and actions: read (workflow-run metadata) at job level; the - # caller must grant at least that or the run startup-fails. + # The pinned reusable (post-standards-#500) needs only `contents: read`: + # its gitleaks job runs a pinned checksum-verified binary and posts no PR + # comments, so the old `pull-requests: write` + `actions: read` caller + # guidance is obsolete (see the PERMISSIONS note in the reusable itself). + # A job-level block REPLACES the workflow-level one for this job. permissions: contents: read uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a diff --git a/project-wharf/crates/wharf-core/src/crypto.rs b/project-wharf/crates/wharf-core/src/crypto.rs index 74d775b..f13a051 100644 --- a/project-wharf/crates/wharf-core/src/crypto.rs +++ b/project-wharf/crates/wharf-core/src/crypto.rs @@ -825,7 +825,8 @@ mod tests { fn test_keypair_encrypted_roundtrip() { let keypair = generate_hybrid_keypair().unwrap(); let pubkey_before = hybrid_public_key(&keypair); - let password = b"test-password-wharf"; + // Not a credential: fixed test fixture for password-based keypair encryption. + let password = b"test-password-wharf"; // scanner-allow: rust-secrets let encrypted = serialize_keypair(&keypair, password).unwrap(); let restored = deserialize_keypair(&encrypted, password).unwrap(); From 5fe05bb827347382c444a6931bcc5f4b28252fa5 Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 25 Sep 2026 22:04:24 +0000 Subject: [PATCH 3/5] chore(praxis): strip dead manifest entries from dashboard and swarm packages The language purge (2966736) deleted the TS sources these entries pointed at; drop unresolvable main/types/bin/scripts so the manifests are honest config shells. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- praxis/SymbolicEngine/dashboard/package.json | 8 -------- praxis/SymbolicEngine/swarm/package.json | 14 +------------- 2 files changed, 1 insertion(+), 21 deletions(-) diff --git a/praxis/SymbolicEngine/dashboard/package.json b/praxis/SymbolicEngine/dashboard/package.json index 36be36f..6c1b6f2 100644 --- a/praxis/SymbolicEngine/dashboard/package.json +++ b/praxis/SymbolicEngine/dashboard/package.json @@ -3,16 +3,8 @@ "version": "0.1.0", "description": "WP Praxis Symbolic Engine Dashboard - Real-time monitoring and control interface", "type": "module", - "main": "src/api-server.ts", "scripts": { - "dev": "bun run --watch src/api-server.ts", - "start": "bun run src/api-server.ts", - "build": "bun build src/api-server.ts --outdir=dist --target=bun", - "build:frontend": "bun build js/dashboard.ts js/workflow-visualizer.ts js/symbol-inspector.ts --outdir=dist/public/js --target=browser", - "build:injector": "bun build injector/js/injector.ts --outdir=dist/public/injector/js --target=browser", - "build:all": "bun run build && bun run build:frontend && bun run build:injector", "test": "bun test", - "lint": "eslint src/**/*.ts js/**/*.ts injector/**/*.ts", "format": "prettier --write \"**/*.{ts,js,json,css,html}\"" }, "dependencies": { diff --git a/praxis/SymbolicEngine/swarm/package.json b/praxis/SymbolicEngine/swarm/package.json index 4d0d784..d89c63c 100644 --- a/praxis/SymbolicEngine/swarm/package.json +++ b/praxis/SymbolicEngine/swarm/package.json @@ -3,20 +3,8 @@ "version": "0.1.0", "description": "Distributed symbolic execution swarm coordinator for WP Praxis", "type": "module", - "main": "dist/index.js", - "types": "dist/index.d.ts", - "bin": { - "swarm": "./bin/swarm-cli.ts" - }, "scripts": { - "build": "bun build src/index.ts --outdir dist --target bun", - "dev": "bun run --watch src/index.ts", - "test": "bun test", - "lint": "tsc --noEmit", - "start:dispatcher": "bun run src/dispatch.ts", - "start:worker": "bun run src/worker.ts", - "start:websocket": "bun run src/websocket-server.ts", - "cli": "bun run bin/swarm-cli.ts" + "test": "bun test" }, "dependencies": { "yaml": "^2.3.4", From 65062c300bd582499baeb4be75ab6604340918ac Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 25 Sep 2026 22:05:33 +0000 Subject: [PATCH 4/5] ci: promote project workflows to root so they can actually run Only root .github/workflows/ runs in this repository; 104 nested copies are inert upstream reference. Promote the four useful ones (git mv + adapt): - project-wharf rust-ci -> project-wharf-rust-ci.yml (cargo fmt/clippy/test + audit) - journal-theme rust-ci -> journal-theme-rust-ci.yml (wasm crate checks) - journal-theme php-standards -> journal-theme-php-standards.yml (phpcs/phpstan/ compat/theme-check); repinned unresolvable upload-artifact@ea165f8d to v7.0.0 - plugin-conflict-mapper php.yml -> plugin-conflict-mapper-php.yml (composer) Each gets a unique name, on: paths scoping (project/** + its own workflow file), defaults.run.working-directory, and a permissions block (required by the standards SPDX/permissions gate). actions.lock covers every uses: pin. Remaining nested workflows stay in place as upstream reference (see #92). Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- .github/workflows/actions.lock | 61 +++++++++++++++++++ .../workflows/journal-theme-php-standards.yml | 32 +++++----- .../workflows/journal-theme-rust-ci.yml | 24 +++++++- .../workflows/plugin-conflict-mapper-php.yml | 20 +++++- .../workflows/project-wharf-rust-ci.yml | 23 ++++++- 5 files changed, 139 insertions(+), 21 deletions(-) rename journal-theme/.github/workflows/php-standards.yml => .github/workflows/journal-theme-php-standards.yml (94%) rename journal-theme/.github/workflows/rust-ci.yml => .github/workflows/journal-theme-rust-ci.yml (77%) rename plugin-conflict-mapper/.github/workflows/php.yml => .github/workflows/plugin-conflict-mapper-php.yml (65%) rename project-wharf/.github/workflows/rust-ci.yml => .github/workflows/project-wharf-rust-ci.yml (79%) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 41e8529..22626fa 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -16,6 +16,15 @@ workflows: '.github/workflows/hypatia-scan.yml': [] '.github/workflows/instant-sync.yml': - 'peter-evans/repository-dispatch@v4.0.1' + '.github/workflows/journal-theme-php-standards.yml': + - 'actions/cache@5a3ec84eff668545956fd18022155c47e93e2684' + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f' + - 'shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240' + '.github/workflows/journal-theme-rust-ci.yml': + - 'Swatinem/rust-cache@779680da715d629ac1d338a641029a2f4372abb5' + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87' '.github/workflows/label-triage.yml': [] '.github/workflows/labels.yml': [] '.github/workflows/mirror.yml': [] @@ -23,6 +32,13 @@ workflows: - 'actions/checkout@v7.0.1' - 'actions/deploy-pages@v5.0.1' - 'actions/upload-pages-artifact@v5.0.0' + '.github/workflows/plugin-conflict-mapper-php.yml': + - 'actions/cache@5a3ec84eff668545956fd18022155c47e93e2684' + - 'actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683' + '.github/workflows/project-wharf-rust-ci.yml': + - 'Swatinem/rust-cache@9d47c6ad4b02e050fd481d890b2ea34778fd09d6' + - 'actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11' + - 'dtolnay/rust-toolchain@d0592fe69e35bc8f12e3dbaf9ad2694d976cb8e3' '.github/workflows/push-email-notify.yml': - 'hyperpolymath/smtp-notify-action@v0.3.0' '.github/workflows/scorecard.yml': [] @@ -120,3 +136,48 @@ dependencies: commit: 'sha1-e83874834305fe9a4a2997156cb26c5de65a8555' owner_id: 135788 repo_id: 208510314 + 'actions/cache@5a3ec84eff668545956fd18022155c47e93e2684': + ref: 'v4' + commit: 'sha1-5a3ec84eff668545956fd18022155c47e93e2684' + owner_id: 44036562 + repo_id: 215566462 + 'actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683': + ref: 'v4' + commit: 'sha1-11bd71901bbe5b1630ceea73d27597364c9af683' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11': + ref: 'v4' + commit: 'sha1-b4ffde65f46336ab88eb53be808477a3936bae11' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd': + ref: 'v6' + commit: 'sha1-de0fac2e4500dabe0009e67214ff5f5447ce83dd' + owner_id: 44036562 + repo_id: 197814629 + 'dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87': + ref: 'stable' + commit: 'sha1-6bed0761d98439e5a578e2877258200ad565ba87' + owner_id: 1940490 + repo_id: 260749683 + 'dtolnay/rust-toolchain@d0592fe69e35bc8f12e3dbaf9ad2694d976cb8e3': + ref: 'stable' + commit: 'sha1-d0592fe69e35bc8f12e3dbaf9ad2694d976cb8e3' + owner_id: 1940490 + repo_id: 260749683 + 'Swatinem/rust-cache@779680da715d629ac1d338a641029a2f4372abb5': + ref: 'v2' + commit: 'sha1-779680da715d629ac1d338a641029a2f4372abb5' + owner_id: 580492 + repo_id: 298565987 + 'Swatinem/rust-cache@9d47c6ad4b02e050fd481d890b2ea34778fd09d6': + ref: 'v2' + commit: 'sha1-9d47c6ad4b02e050fd481d890b2ea34778fd09d6' + owner_id: 580492 + repo_id: 298565987 + 'shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240': + ref: 'v2' + commit: 'sha1-f3e473d116dcccaddc5834248c87452386958240' + owner_id: 1571086 + repo_id: 206578964 diff --git a/journal-theme/.github/workflows/php-standards.yml b/.github/workflows/journal-theme-php-standards.yml similarity index 94% rename from journal-theme/.github/workflows/php-standards.yml rename to .github/workflows/journal-theme-php-standards.yml index 5775d8a..e5f70e3 100644 --- a/journal-theme/.github/workflows/php-standards.yml +++ b/.github/workflows/journal-theme-php-standards.yml @@ -1,26 +1,28 @@ # SPDX-License-Identifier: MPL-2.0 -name: PHP/WordPress Standards +# +# Promoted from journal-theme/.github/workflows/php-standards.yml (only root +# workflows run in this repo; the vendored copy is upstream history). +name: Journal Theme PHP/WordPress Standards + on: push: branches: [main, develop] paths: - - '**.php' - - 'phpcs.xml.dist' - - 'phpstan.neon' - - 'composer.json' - - 'composer.lock' - - '.github/workflows/php-standards.yml' + - 'journal-theme/**' + - '.github/workflows/journal-theme-php-standards.yml' pull_request: branches: [main, develop] paths: - - '**.php' - - 'phpcs.xml.dist' - - 'phpstan.neon' - - 'composer.json' - - 'composer.lock' - - '.github/workflows/php-standards.yml' + - 'journal-theme/**' + - '.github/workflows/journal-theme-php-standards.yml' + permissions: contents: read + +defaults: + run: + working-directory: journal-theme + jobs: phpcs: name: WordPress Coding Standards @@ -53,10 +55,10 @@ jobs: run: cs2pr ./phpcs-report.xml - name: Upload PHPCS report if: failure() - uses: actions/upload-artifact@ea165f8d65b6db9a8b71b5c2d1a090c0daf9c8bb # v4 + uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 (repinned: vendored ea165f8d does not resolve) with: name: phpcs-report - path: phpcs-report.xml + path: journal-theme/phpcs-report.xml phpstan: name: PHPStan Static Analysis runs-on: ubuntu-latest diff --git a/journal-theme/.github/workflows/rust-ci.yml b/.github/workflows/journal-theme-rust-ci.yml similarity index 77% rename from journal-theme/.github/workflows/rust-ci.yml rename to .github/workflows/journal-theme-rust-ci.yml index 1f54e9c..6580ec3 100644 --- a/journal-theme/.github/workflows/rust-ci.yml +++ b/.github/workflows/journal-theme-rust-ci.yml @@ -1,9 +1,29 @@ # SPDX-License-Identifier: MPL-2.0 -name: Rust CI -on: [push, pull_request] +# +# Promoted from journal-theme/.github/workflows/rust-ci.yml (only root +# workflows run in this repo; the vendored copy is upstream history). +name: Journal Theme Rust CI + +on: + push: + paths: + - 'journal-theme/**' + - '.github/workflows/journal-theme-rust-ci.yml' + pull_request: + paths: + - 'journal-theme/**' + - '.github/workflows/journal-theme-rust-ci.yml' + +permissions: contents: read + env: CARGO_TERM_COLOR: always RUSTFLAGS: -Dwarnings + +defaults: + run: + working-directory: journal-theme + jobs: test: runs-on: ubuntu-latest diff --git a/plugin-conflict-mapper/.github/workflows/php.yml b/.github/workflows/plugin-conflict-mapper-php.yml similarity index 65% rename from plugin-conflict-mapper/.github/workflows/php.yml rename to .github/workflows/plugin-conflict-mapper-php.yml index 3188c2b..83a238e 100644 --- a/plugin-conflict-mapper/.github/workflows/php.yml +++ b/.github/workflows/plugin-conflict-mapper-php.yml @@ -1,12 +1,28 @@ # SPDX-License-Identifier: MPL-2.0 -name: PHP Composer +# +# Promoted from plugin-conflict-mapper/.github/workflows/php.yml (only root +# workflows run in this repo; the vendored copy is upstream history). +name: Plugin Conflict Mapper PHP Composer + on: push: branches: ["main"] + paths: + - 'plugin-conflict-mapper/**' + - '.github/workflows/plugin-conflict-mapper-php.yml' pull_request: branches: ["main"] + paths: + - 'plugin-conflict-mapper/**' + - '.github/workflows/plugin-conflict-mapper-php.yml' + permissions: contents: read + +defaults: + run: + working-directory: plugin-conflict-mapper + jobs: build: runs-on: ubuntu-latest @@ -19,7 +35,7 @@ jobs: id: composer-cache uses: actions/cache@5a3ec84eff668545956fd18022155c47e93e2684 # v4 with: - path: vendor + path: plugin-conflict-mapper/vendor key: ${{ runner.os }}-php-${{ hashFiles('**/composer.lock') }} restore-keys: | ${{ runner.os }}-php- diff --git a/project-wharf/.github/workflows/rust-ci.yml b/.github/workflows/project-wharf-rust-ci.yml similarity index 79% rename from project-wharf/.github/workflows/rust-ci.yml rename to .github/workflows/project-wharf-rust-ci.yml index 0b6018c..86a5061 100644 --- a/project-wharf/.github/workflows/rust-ci.yml +++ b/.github/workflows/project-wharf-rust-ci.yml @@ -1,11 +1,30 @@ # SPDX-License-Identifier: MPL-2.0 # SPDX-FileCopyrightText: 2025 Jonathan D.A. Jewell -name: Rust CI -on: [push, pull_request] +# +# Promoted from project-wharf/.github/workflows/rust-ci.yml (only root +# workflows run in this repo; the vendored copy is upstream history). +name: Project Wharf Rust CI + +on: + push: + paths: + - 'project-wharf/**' + - '.github/workflows/project-wharf-rust-ci.yml' + pull_request: + paths: + - 'project-wharf/**' + - '.github/workflows/project-wharf-rust-ci.yml' + permissions: read-all + env: CARGO_TERM_COLOR: always RUSTFLAGS: -Dwarnings + +defaults: + run: + working-directory: project-wharf + jobs: test: runs-on: ubuntu-latest From d6954b22fc22f43bfa9046a8b405452f31772ee3 Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 25 Sep 2026 22:06:08 +0000 Subject: [PATCH 5/5] fix: nested permissions mapping in journal-theme-rust-ci (one-liner form is invalid YAML) Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- .github/workflows/journal-theme-rust-ci.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/journal-theme-rust-ci.yml b/.github/workflows/journal-theme-rust-ci.yml index 6580ec3..aaf4a2c 100644 --- a/.github/workflows/journal-theme-rust-ci.yml +++ b/.github/workflows/journal-theme-rust-ci.yml @@ -14,7 +14,8 @@ on: - 'journal-theme/**' - '.github/workflows/journal-theme-rust-ci.yml' -permissions: contents: read +permissions: + contents: read env: CARGO_TERM_COLOR: always