diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 26eefe5..ec133c9 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -9,10 +9,10 @@ workflows: '.github/workflows/labels.yml': [] '.github/workflows/secret-scanner.yml': [] '.github/workflows/push-email-notify.yml': - - 'dawidd6/action-send-mail@v3.12.0' + - 'hyperpolymath/smtp-notify-action@v0.1.0' dependencies: - 'dawidd6/action-send-mail@v3.12.0': - ref: 'v3.12.0' - commit: 'sha1-6e502825a508b867ab2954ad6343b68787624c01' - owner_id: 9713907 - repo_id: 222439721 + 'hyperpolymath/smtp-notify-action@v0.1.0': + ref: 'v0.1.0' + commit: 'sha1-1b3b752d39a4fe4c0f28f10905e4608789d3e050' + owner_id: 6759885 + repo_id: 1352485172 diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index 360340c..ece395b 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -4,20 +4,27 @@ # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by # new repos from the template; placed on existing repos by the farm sweep. +# +# Re-landed after the 2026-07-20 notification-storm freeze (removed in +# 09f94c5), now on hyperpolymath/smtp-notify-action: Node-free, the SMTP +# session is Idris2-specified and machine-checked, the binary is Zig-built, +# byte-reproducible, and SHA-256-pinned inside the action itself. name: Push email notification on: - push: {} + push: + # Branch pushes only: tag and deletion payloads mislabel Branch:/head_commit. + branches: ['**'] permissions: - actions: read contents: read jobs: notify: name: Email on push if: ${{ vars.PUSH_EMAIL_ENABLED == 'true' }} runs-on: ubuntu-latest + timeout-minutes: 5 steps: - name: Send push notification email - uses: dawidd6/action-send-mail@v3.12.0 + uses: hyperpolymath/smtp-notify-action@v0.1.0 # NOSONAR — pin authority is actions.lock (sha1-1b3b752d39a4fe4c0f28f10905e4608789d3e050) with: server_address: ${{ secrets.SMTP_HOST }} server_port: ${{ secrets.SMTP_PORT }}