-
Notifications
You must be signed in to change notification settings - Fork 0
chore(ci): repoint push-email-notify to smtp-notify-action #58
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -3,19 +3,43 @@ | |
| # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; | ||
| # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by | ||
| # new repos from the template; placed on existing repos by the farm sweep. | ||
| # | ||
| # Re-landed after the 2026-07-20 notification-storm freeze (removed in | ||
| # 09f94c5), now on hyperpolymath/smtp-notify-action: Node-free, the SMTP | ||
| # session is Idris2-specified and machine-checked, the binary is Zig-built, | ||
| # byte-reproducible, and SHA-256-pinned inside the action itself. | ||
| name: Push email notification | ||
| on: | ||
| push: {} | ||
| push: | ||
| # Branch pushes only: tag and deletion payloads mislabel Branch:/head_commit. | ||
| branches: ['**'] | ||
| concurrency: | ||
| # Deliberately per-RUN, so no run is ever queued behind another and none is | ||
| # ever cancelled. Do NOT "tidy" this into a shared group such as | ||
| # ${{ github.workflow }}-${{ github.ref }}. GitHub's workflow-syntax docs: | ||
| # "By default, any existing pending job or workflow in the same concurrency | ||
| # group will be canceled and the new queued job or workflow will take its | ||
| # place." That happens regardless of cancel-in-progress, which governs only | ||
| # the RUNNING job. On this workflow it silently loses a notification email, | ||
| # with no error anywhere. Every run here reports a DISTINCT commit, so there | ||
| # is no redundant work for a concurrency limit to remove. | ||
| # The docs also offer `queue: max` (up to 100 pending); not used, because 100 | ||
| # is still a cap whereas a per-run group needs none. | ||
| # Verified with zizmor 1.30.0: deleting this block raises concurrency-limits; | ||
| # this form silences it exactly as a shared group would. | ||
| group: push-email-${{ github.run_id }} | ||
| cancel-in-progress: false | ||
| permissions: | ||
| contents: read | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: sed -n '1,140p' .github/workflows/push-email-notify.yml
printf '\n--- pinned action metadata ---\n'
curl -fsSL https://raw.githubusercontent.com/hyperpolymath/smtp-notify-action/ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7/action.ymlRepository: hyperpolymath/error-lang Length of output: 8530 Use an empty token permission set for this mail-only job. The workflow does not check out repository contents or call the GitHub API. If no other step needs 🤖 Prompt for AI AgentsSource: MCP tools |
||
| jobs: | ||
| notify: | ||
| name: Email on push | ||
| if: ${{ vars.PUSH_EMAIL_ENABLED == 'true' }} | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 5 | ||
| steps: | ||
| - name: Send push notification email | ||
| uses: dawidd6/action-send-mail@6e502825a508b867ab2954ad6343b68787624c01 # pinned | ||
| uses: hyperpolymath/smtp-notify-action@ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7 # v0.2.0 | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: #!/usr/bin/env bash
set -euo pipefail
rg -n -C 2 'SMTP_(HOST|PORT)|smtp\.office365\.com|server_port|secure:|587|465' .
curl -fsSL 'https://raw.githubusercontent.com/hyperpolymath/smtp-notify-action/ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7/MIGRATION.adoc' |
rg -n 'STARTTLS|AUTH PLAIN|Microsoft 365|port 465|port 587|secure'Repository: hyperpolymath/error-lang Length of output: 2493 Verify the SMTP endpoint before switching actions. The action uses implicit TLS when 🤖 Prompt for AI AgentsSource: MCP tools |
||
| with: | ||
| server_address: ${{ secrets.SMTP_HOST }} | ||
| server_port: ${{ secrets.SMTP_PORT }} | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
Repository: hyperpolymath/error-lang
Length of output: 13418
🌐 Web query:
GitHub Actions push event branches filter branch deletion deleted true head_commit null official documentation💡 Result:
In GitHub Actions, the
pushevent is triggered not only by pushes of commits or tags but also when a branch is deleted [1][2]. When a branch is deleted, thepushevent payload reflects this activity, and thehead_commitattribute is typicallynullbecause there is no "head" commit associated with the deletion event itself [2][3][4]. Regarding branch filters (on.push.branches), GitHub's documentation specifies that filters control which events trigger the workflow [5][6]. When a branch is deleted, thepushevent behaves according to the repository's configuration. Because branch deletion is a form ofpushevent, if you have branch filters defined, the workflow will only trigger if the deleted branch name matches yourbranchesorbranches-ignorepatterns [6][7]. To handle or ignore branch deletions within your workflow, you can inspect the event payload context. Thegithub.eventobject provides thedeletedboolean property, which is set totruewhen the push event represents a branch deletion [2][3]. Common strategies to manage this behavior include: 1. Using conditional logic (theifkeyword) in your workflow jobs to explicitly skip runs when a deletion occurs: if: ${{!github.event.deleted }} 2. If you specifically need to respond to deletions, you should generally use thedeleteevent type instead of thepushevent, as it is designed specifically for this activity [2]. Thedeleteevent payload contains the name of the deleted ref (branch or tag) viagithub.event.ref[8]. If you rely on thepushevent for your workflow, be aware that thehead_commitattribute beingnullis expected during deletion, and attempting to access fields withinhead_commitwithout checking if it is null will cause your workflow to fail [9][4]. Always ensure your conditional expressions safely handle the structure of the event payload [1].Citations:
Exclude deleted branch refs explicitly.
branches: ['**']also matches a deleted branch ref. The job can then run withgithub.event.deleted == trueand nohead_commit. Addgithub.event.deleted == falseto the job condition.🤖 Prompt for AI Agents
Source: MCP tools