{"id":20641934,"url":"https://github.com/clechasseur/rs-fmt-check","last_synced_at":"2026-05-02T08:34:39.888Z","repository":{"id":188394195,"uuid":"678662485","full_name":"clechasseur/rs-fmt-check","owner":"clechasseur","description":"📋 GitHub Action for PR annotations with rustfmt suggestions","archived":false,"fork":false,"pushed_at":"2026-04-23T21:20:51.000Z","size":5235,"stargazers_count":1,"open_issues_count":3,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-04-23T23:27:14.174Z","etag":null,"topics":["github-actions","rust","rust-lang","rustfmt"],"latest_commit_sha":null,"homepage":"","language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/clechasseur.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2023-08-15T04:16:32.000Z","updated_at":"2026-04-23T21:20:16.000Z","dependencies_parsed_at":"2025-12-29T07:05:25.763Z","dependency_job_id":null,"html_url":"https://github.com/clechasseur/rs-fmt-check","commit_stats":null,"previous_names":["clechasseur/rs-fmt-check"],"tags_count":23,"template":false,"template_full_name":"clechasseur/rs-clippy-check","purl":"pkg:github/clechasseur/rs-fmt-check","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/clechasseur%2Frs-fmt-check","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/clechasseur%2Frs-fmt-check/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/clechasseur%2Frs-fmt-check/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/clechasseur%2Frs-fmt-check/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/clechasseur","download_url":"https://codeload.github.com/clechasseur/rs-fmt-check/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/clechasseur%2Frs-fmt-check/sbom","scorecard":{"id":291158,"data":{"date":"2025-08-11","repo":{"name":"github.com/clechasseur/rs-fmt-check","commit":"e9b1eed9abc16e468c05db98f44ec1ac17f4ffc4"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":5.5,"checks":[{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/check-dist.yml:1","Warn: no topLevel permission defined: .github/workflows/ci.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Maintained","score":10,"reason":"19 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Pinned-Dependencies","score":10,"reason":"all dependencies are pinned","details":["Info:   6 out of   6 GitHub-owned GitHubAction dependencies pinned","Info:   1 out of   1 third-party GitHubAction dependencies pinned","Info:   2 out of   2 npmCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Code-Review","score":0,"reason":"Found 0/4 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 29 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-17T18:14:25.609Z","repository_id":188394195,"created_at":"2025-08-17T18:14:25.610Z","updated_at":"2025-08-17T18:14:25.610Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32528363,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-02T01:12:54.858Z","status":"online","status_checked_at":"2026-05-02T02:00:05.923Z","response_time":132,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["github-actions","rust","rust-lang","rustfmt"],"created_at":"2024-11-16T16:07:18.471Z","updated_at":"2026-05-02T08:34:39.883Z","avatar_url":"https://github.com/clechasseur.png","language":"TypeScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"# `rs-fmt-check` Action\n\n[![MIT licensed](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE)\n[![CI](https://github.com/clechasseur/rs-fmt-check/actions/workflows/ci.yml/badge.svg?branch=main\u0026event=push)](https://github.com/clechasseur/rs-fmt-check/actions/workflows/ci.yml)\n\n\u003e Rustfmt suggestions in your Pull Requests\n\nThis GitHub Action executes [`rustfmt`](https://github.com/rust-lang/rustfmt) and posts all suggestions as annotations for the pushed commit [\u003csup\u003e2\u003c/sup\u003e](#note-annotations-limit).\n\n![Screenshot of a rustfmt suggestion displayed in the commit interface of GitHub](./.github/screenshot_fmt.png)\n\nThis GitHub Action is based on [clechasseur/rs-clippy-check](https://github.com/clechasseur/rs-clippy-check), which itself has been forked from [actions-rs/clippy-check](https://github.com/actions-rs/clippy-check).\nSee [LICENSE](LICENSE) for copyright attribution details.\n\n## Example workflow\n\nNote: this workflow uses [`actions-rust-lang/setup-rust-toolchain`](https://github.com/actions-rust-lang/setup-rust-toolchain) to install the most recent `nightly` rustfmt [\u003csup\u003e1\u003c/sup\u003e](#note-nightly-requirement).\n\n```yaml\nname: Rustfmt check\n\non: push\n\njobs:\n  rustfmt_check:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2\n      - uses: actions-rust-lang/setup-rust-toolchain@6044e13b5dc448c55e2357c09f80417699197238 # v6.2.0\n        with:\n          toolchain: nightly\n          components: rustfmt\n      - uses: clechasseur/rs-fmt-check@v4.0.3\n```\n\n## Inputs\n\nAll inputs are optional.\n\n| Name | Description                                                     | Type | Default |\n| --- |-----------------------------------------------------------------| --- | --- |\n| `toolchain` | Rust toolchain to use [\u003csup\u003e1\u003c/sup\u003e](#note-nightly-requirement) | string | `nightly` |\n| `args` | Arguments for the `cargo fmt` command                           | string |         |\n| `working-directory` | Directory where to perform the `cargo fmt` command              | string |         |\n\nFor extra details about the `toolchain` and `args` inputs, see [`rs-cargo` Action](https://github.com/clechasseur/rs-cargo#inputs).\n\n## Release immutability\n\nStarting with release 4.0.0, this GitHub action's releases will be marked as [immutable](https://docs.github.com/en/code-security/concepts/supply-chain-security/immutable-releases). This means that once a release is created, its tag cannot be modified in any way.\n\nPreviously, best practices for using GitHub actions in workflows were to pin the actions to a specific Git commit hash. With immutable releases, this is no longer necessary and the actual Git tag is safe to use. Because of this, starting with release 4.0.0, this GitHub action will **no longer provide a floating major version tag** (like `v4`, for example). To use a specific version of this action, pin it to the release tag (like `v4.0.0`).\n\n## Notes\n\n\u003ca name=\"note-nightly-requirement\"\u003e\u003csup\u003e1\u003c/sup\u003e\u003c/a\u003e : This action currently relies on an unstable `rustfmt` feature (`emit json`) and as such, requires a `nightly` toolchain at the minimum. You should not change the value of the `toolchain` parameter unless you know the specified toolchain supports the feature correctly.\n\n\u003ca name=\"note-annotations-limit\"\u003e\u003csup\u003e2\u003c/sup\u003e\u003c/a\u003e : Currently, GitHub sets a limit of 10 warning annotations per run (see [this page](https://docs.github.com/en/rest/checks/runs?apiVersion=2022-11-28) for more information). So if there are more than 10 suggestions returned by `rustfmt`, only the first 10 will appear as PR annotations. The other suggestions will still appear in the check run summary (see [this one](https://github.com/clechasseur/rs-fmt-check/actions/runs/5886828621/attempts/1#summary-15965282231) for example).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fclechasseur%2Frs-fmt-check","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fclechasseur%2Frs-fmt-check","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fclechasseur%2Frs-fmt-check/lists"}