-
-
Notifications
You must be signed in to change notification settings - Fork 0
chore(ci): repoint push-email-notify to smtp-notify-action #54
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -4,19 +4,43 @@ | |
| # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; | ||
| # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by | ||
| # new repos from the template; placed on existing repos by the farm sweep. | ||
| # | ||
| # Re-landed after the 2026-07-20 notification-storm freeze (removed in | ||
| # 09f94c5), now on hyperpolymath/smtp-notify-action: Node-free, the SMTP | ||
| # session is Idris2-specified and machine-checked, the binary is Zig-built, | ||
| # byte-reproducible, and SHA-256-pinned inside the action itself. | ||
| name: Push email notification | ||
| on: | ||
| push: {} | ||
| push: | ||
| # Branch pushes only: tag and deletion payloads mislabel Branch:/head_commit. | ||
| branches: ['**'] | ||
| concurrency: | ||
| # Deliberately per-RUN, so no run is ever queued behind another and none is | ||
| # ever cancelled. Do NOT "tidy" this into a shared group such as | ||
| # ${{ github.workflow }}-${{ github.ref }}. GitHub's workflow-syntax docs: | ||
| # "By default, any existing pending job or workflow in the same concurrency | ||
| # group will be canceled and the new queued job or workflow will take its | ||
| # place." That happens regardless of cancel-in-progress, which governs only | ||
| # the RUNNING job. On this workflow it silently loses a notification email, | ||
| # with no error anywhere. Every run here reports a DISTINCT commit, so there | ||
| # is no redundant work for a concurrency limit to remove. | ||
| # The docs also offer `queue: max` (up to 100 pending); not used, because 100 | ||
| # is still a cap whereas a per-run group needs none. | ||
| # Verified with zizmor 1.30.0: deleting this block raises concurrency-limits; | ||
| # this form silences it exactly as a shared group would. | ||
| group: push-email-${{ github.run_id }} | ||
| cancel-in-progress: false | ||
| permissions: | ||
| contents: read | ||
| jobs: | ||
| notify: | ||
| name: Email on push | ||
| if: ${{ vars.PUSH_EMAIL_ENABLED == 'true' }} | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 5 | ||
| steps: | ||
| - name: Send push notification email | ||
| uses: dawidd6/action-send-mail@94de994a9f6fffee200243214e17002e2920bb59 # v18 | ||
| uses: hyperpolymath/smtp-notify-action@v0.2.0 # NOSONAR — pin authority is actions.lock (sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7) | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🩺 Stability & Availability | 🟡 Minor | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/push-email-notify.yml | sed -n '1,100p'
printf '%s\n' '--- lock entry ---'
rg -n -C 3 'smtp-notify|ede1191|SMTP_PORT' .github/workflows/actions.lock .github/workflows/push-email-notify.yml
printf '%s\n' '--- action metadata at pinned commit ---'
curl -fsSL https://raw.githubusercontent.com/hyperpolymath/smtp-notify-action/ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7/action.ymlRepository: hyperpolymath/lucidscript Length of output: 11853 Confirm that The workflow passes 🤖 Prompt for AI AgentsSource: MCP tools 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: printf '%s\n' '--- workflow ---'
sed -n '35,48p' .github/workflows/push-email-notify.yml
printf '%s\n' '--- lock entry ---'
rg -n -C 2 'smtp-notify-action|ede1191' .github/workflows/actions.lockRepository: hyperpolymath/lucidscript Length of output: 1231 🏁 Script executed: set -eu
api='https://api.github.com/repos/hyperpolymath/smtp-notify-action'
ref_json="$(curl -fsSL "$api/git/ref/tags/v0.2.0")"
printf '%s\n' '--- tag ref ---'
printf '%s\n' "$ref_json" | jq '{type: .object.type, sha: .object.sha}'
type="$(printf '%s\n' "$ref_json" | jq -r '.object.type')"
sha="$(printf '%s\n' "$ref_json" | jq -r '.object.sha')"
if [ "$type" = tag ]; then
printf '%s\n' '--- annotated tag target ---'
curl -fsSL "$api/git/tags/$sha" | jq '{type: .object.type, sha: .object.sha}'
sha="$(curl -fsSL "$api/git/tags/$sha" | jq -r '.object.sha')"
fi
printf '%s\n' '--- resolved commit ---'
curl -fsSL "$api/commits/$sha" | jq '{sha: .sha, message: .commit.message}'
printf '%s\n' '--- locked SHA resolution ---'
curl -fsSL "$api/commits/ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7" | jq '{sha: .sha, message: .commit.message}'Repository: hyperpolymath/lucidscript Length of output: 3491 Pin the action at the locked commit SHA. Line 43 still uses the mutable 🤖 Prompt for AI AgentsSource: MCP tools |
||
| with: | ||
| server_address: ${{ secrets.SMTP_HOST }} | ||
| server_port: ${{ secrets.SMTP_PORT }} | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
Repository: hyperpolymath/lucidscript
Length of output: 7440
🌐 Web query:
GitHub Actions workflow syntax branches push deleted branch event branches filter deleted true💡 Result:
There is no parameter called deleted: true in the GitHub Actions workflow syntax for filtering branch pushes [1][2][3]. The GitHub Actions
pushevent triggers workflows for various activity types, including branch deletions [4][5]. Because thepushevent includes deletions, workflows configured withon: pushmay unintentionally run when a branch is deleted [6]. To control or filter this behavior: 1. Use thedeleteevent: If you specifically want to trigger a workflow when a branch is deleted, use thedeleteevent instead ofpush[7][5]. Note that thedeleteevent workflow must exist on the default branch of the repository to trigger [7]. 2. Add manual filtering: Since there is no built-indeleted: truefilter, you can add a step to your workflow to check the event payload and exit early if the push represents a deletion [6]. The push event payload contains adeletedboolean field [4] that can be used within a conditional step: jobs: my_job: runs-on: ubuntu-latest if: ${{!github.event.deleted }} steps: - run: echo "This workflow will not run if the branch was deleted." This conditional logic prevents the job from executing when thepushevent corresponds to a branch deletion [4].Citations:
🏁 Script executed:
Repository: hyperpolymath/lucidscript
Length of output: 11789
🌐 Web query:
site:docs.github.com actions push event branch deletion branches filter github.event.deleted head_commit null💡 Result:
When a branch is deleted in a GitHub repository, it triggers a push event to the repository [1][2]. In the resulting webhook payload, the
deletedfield is set totrue[1], and thehead_commitobject is typicallynullbecause the branch no longer exists to point to a head commit [1][2]. If you are using GitHub Actions and a workflow is configured to run on thepushevent, that workflow will be triggered by branch deletion events [3][4]. To prevent your workflow from running or failing when a branch is deleted, you can add a conditional check in your workflow YAML file to detect if the branch deletion occurred [1]. You can use the following syntax in your workflow job steps or at the job level: if: ${{!github.event.deleted }} This conditional check ensures that the step (or job) only executes when the push event is not a branch deletion [1]. Additionally, when a branch is deleted, theGITHUB_SHAin the workflow run defaults to the SHA of the tip commit of the repository's default branch [3][4]. If your logic relies on thehead_commit, checking forgithub.event.deletedis the standard way to handle this scenario gracefully [1].Citations:
Exclude deleted branch pushes
When
PUSH_EMAIL_ENABLEDistrue, branch deletion triggers thispushworkflow. The payload can havedeleted: trueand nohead_commit, so the notification can contain an emptyHead msg. Addgithub.event.deleted != truetojobs.notify.if.🤖 Prompt for AI Agents
Source: MCP tools