- Split GH_TOKEN away from binary smoke-test step to prevent token exfiltration via compromised release artifact - Wrap gh subprocess calls in try/except FileNotFoundError so the guard degrades gracefully when gh CLI is not installed - Remove stderr suppression from cargo check --locked so diagnostics are visible on failure |
||
|---|---|---|
| .. | ||
| codeql | ||
| connectivity | ||
| ISSUE_TEMPLATE | ||
| release | ||
| security | ||
| workflows | ||
| actionlint.yaml | ||
| CODEOWNERS | ||
| dependabot.yml | ||
| label-policy.json | ||
| labeler.yml | ||
| pull_request_template.md | ||