-
-
Notifications
You must be signed in to change notification settings - Fork 0
chore(ci): repoint push-email-notify to smtp-notify-action #62
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -4,19 +4,43 @@ | |
| # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; | ||
| # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by | ||
| # new repos from the template; placed on existing repos by the farm sweep. | ||
| # | ||
| # Re-landed after the 2026-07-20 notification-storm freeze (removed in | ||
| # 09f94c5), now on hyperpolymath/smtp-notify-action: Node-free, the SMTP | ||
| # session is Idris2-specified and machine-checked, the binary is Zig-built, | ||
| # byte-reproducible, and SHA-256-pinned inside the action itself. | ||
| name: Push email notification | ||
| on: | ||
| push: {} | ||
| push: | ||
| # Branch pushes only: tag and deletion payloads mislabel Branch:/head_commit. | ||
| branches: ['**'] | ||
| concurrency: | ||
| # Deliberately per-RUN, so no run is ever queued behind another and none is | ||
| # ever cancelled. Do NOT "tidy" this into a shared group such as | ||
| # ${{ github.workflow }}-${{ github.ref }}. GitHub's workflow-syntax docs: | ||
| # "By default, any existing pending job or workflow in the same concurrency | ||
| # group will be canceled and the new queued job or workflow will take its | ||
| # place." That happens regardless of cancel-in-progress, which governs only | ||
| # the RUNNING job. On this workflow it silently loses a notification email, | ||
| # with no error anywhere. Every run here reports a DISTINCT commit, so there | ||
| # is no redundant work for a concurrency limit to remove. | ||
| # The docs also offer `queue: max` (up to 100 pending); not used, because 100 | ||
| # is still a cap whereas a per-run group needs none. | ||
| # Verified with zizmor 1.30.0: deleting this block raises concurrency-limits; | ||
| # this form silences it exactly as a shared group would. | ||
| group: push-email-${{ github.run_id }} | ||
| cancel-in-progress: false | ||
| permissions: | ||
| contents: read | ||
| jobs: | ||
| notify: | ||
| name: Email on push | ||
| if: ${{ vars.PUSH_EMAIL_ENABLED == 'true' }} | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 5 | ||
| steps: | ||
| - name: Send push notification email | ||
| uses: dawidd6/action-send-mail@v3.12.0 | ||
| uses: hyperpolymath/smtp-notify-action@v0.2.0 # NOSONAR — pin authority is actions.lock (sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7) | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: set -eu
repo='hyperpolymath/smtp-notify-action'
tag='v0.2.0'
sha='ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7'
if command -v gh >/dev/null 2>&1; then
ref_json="$(gh api "repos/${repo}/git/ref/tags/${tag}")"
printf '%s\n' "$ref_json" | jq '{ref: .ref, type: .object.type, sha: .object.sha}'
object_type="$(printf '%s\n' "$ref_json" | jq -r '.object.type')"
object_sha="$(printf '%s\n' "$ref_json" | jq -r '.object.sha')"
if [ "$object_type" = tag ]; then
gh api "repos/${repo}/git/tags/${object_sha}" --jq '{type: .object.type, sha: .object.sha}'
fi
gh api "repos/${repo}/commits/${sha}" --jq '{sha: .sha, message: .commit.message}'
else
ref_json="$(curl -fsSL "https://api.github.com/repos/${repo}/git/ref/tags/${tag}")"
printf '%s\n' "$ref_json" | jq '{ref: .ref, type: .object.type, sha: .object.sha}'
object_type="$(printf '%s\n' "$ref_json" | jq -r '.object.type')"
object_sha="$(printf '%s\n' "$ref_json" | jq -r '.object.sha')"
if [ "$object_type" = tag ]; then
curl -fsSL "https://api.github.com/repos/${repo}/git/tags/${object_sha}" | jq '{type: .object.type, sha: .object.sha}'
fi
curl -fsSL "https://api.github.com/repos/${repo}/commits/${sha}" | jq '{sha: .sha, message: .commit.message}'
fiRepository: hyperpolymath/halideiser Length of output: 1872 Pin the action ref to the locked commit.
🤖 Prompt for AI Agents🩺 Stability & Availability | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/push-email-notify.yml | sed -n '1,90p'
printf '%s\n' '--- lock entry ---'
rg -n -C 3 'hyperpolymath/smtp-notify-action|ede1191|SMTP_PORT|secure' .github/workflows/actions.lock .github/workflows/push-email-notify.ymlRepository: hyperpolymath/halideiser Length of output: 6414 🏁 Script executed: #!/bin/bash
set -eu
url='https://raw.githubusercontent.com/hyperpolymath/smtp-notify-action/ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7/action.yml'
curl --fail --silent --show-error "$url" | sed -n '1,220p'Repository: hyperpolymath/halideiser Length of output: 5655 Confirm the SMTP transport before enabling notifications.
🤖 Prompt for AI Agents |
||
| with: | ||
| server_address: ${{ secrets.SMTP_HOST }} | ||
| server_port: ${{ secrets.SMTP_PORT }} | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
Repository: hyperpolymath/halideiser
Length of output: 21421
🌐 Web query:
GitHub Actions push event branches filter branch deletion deleted true head_commit null workflow syntax💡 Result:
When a branch is deleted on GitHub, the push event is triggered, and the webhook payload includes a
deletedfield set totrue[1][2][3]. During such a deletion event, thehead_commitobject in the payload isnull[2][3]. To prevent workflows from running unintentionally when a branch is deleted, you can use a conditional filter in your workflow'sifstatement [4]. ### Recommended Syntax You can filter out branch deletion events by adding the following condition to your job:yaml jobs: my_job: if: ${{ !github.event.deleted }} runs-on: ubuntu-latest steps: - name: Run code run: echo "This only runs if the branch was not deleted."### Explanation - github.event.deleted: This boolean value is provided by the push webhook payload [2][3]. When a branch is deleted, this is set totrue[1][2]. - head_commit: Because thepushevent for a deletion does not represent a new commit,github.event.head_commitisnull[2][3]. Attempting to access properties ofhead_commit(e.g.,github.event.head_commit.id) in an expression without checking for its existence will cause the workflow to fail. Usingif: ${{ !github.event.deleted }}effectively handles both the deletion trigger and avoids issues with thenullhead_commit. If you need to distinguish between different types of push events or trigger workflows specifically on deletions, you can alternatively use thedeleteevent type [4][2], which is separate from thepushevent. However, for most CI/CD pipelines that need to ignore deletions, the simple conditional check shown above is the standard approach [4].Citations:
🌐 Web query:
site:docs.github.com GitHub Actions expressions property dereference null nonexistent property empty string💡 Result:
In GitHub Actions, if you attempt to dereference a nonexistent property using property dereference syntax (e.g., context.nonexistent), the expression will evaluate to an empty string [1][2]. This behavior is specific to the property dereference syntax. It is important to distinguish this from a null value: - If a property exists but its assigned value is null, the result of the expression is null [3]. - If a property does not exist at all, the result is an empty string [1][2]. In GitHub Actions expressions, falsy values—which include false, 0, "", and null—are coerced to false in conditional contexts (such as an if clause) [3]. Consequently, both an explicit null value and a nonexistent property (which becomes an empty string) will evaluate as false when used in a conditional check [3].
Citations:
Exclude branch-deletion pushes from the workflow.
A branch deletion triggers
pushwithgithub.event.deleted == trueandgithub.event.head_commit == null. When enabled, this job can send a notification without a head commit message. Add!github.event.deletedto the job condition.🤖 Prompt for AI Agents