-
-
Notifications
You must be signed in to change notification settings - Fork 0
chore(ci): repoint push-email-notify to smtp-notify-action #36
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -4,20 +4,27 @@ | |
| # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; | ||
| # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by | ||
| # new repos from the template; placed on existing repos by the farm sweep. | ||
| # | ||
| # Re-landed after the 2026-07-20 notification-storm freeze (removed in | ||
| # 09f94c5), now on hyperpolymath/smtp-notify-action: Node-free, the SMTP | ||
| # session is Idris2-specified and machine-checked, the binary is Zig-built, | ||
| # byte-reproducible, and SHA-256-pinned inside the action itself. | ||
| name: Push email notification | ||
| on: | ||
| push: {} | ||
| push: | ||
| # Branch pushes only: tag and deletion payloads mislabel Branch:/head_commit. | ||
| branches: ['**'] | ||
| permissions: | ||
| actions: read | ||
| contents: read | ||
| jobs: | ||
| notify: | ||
| name: Email on push | ||
| if: ${{ vars.PUSH_EMAIL_ENABLED == 'true' }} | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 5 | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🩺 Stability & Availability | 🔵 Trivial 🔎 Supported by static analysis🏁 Script executed: #!/bin/bash
cat -n .github/workflows/push-email-notify.yml
printf '\nConcurrency declarations:\n'
rg -n '^(concurrency:|[[:space:]]+concurrency:|[[:space:]]+cancel-in-progress:|[[:space:]]+timeout-minutes:)' .github/workflows/push-email-notify.ymlRepository: hyperpolymath/action-trust-layers Length of output: 2428 🌐 Web query:
💡 Result: By default, GitHub Actions allows multiple workflow runs and jobs to execute concurrently [1][2]. There is no automatic restriction on the number of concurrent runs for a workflow unless you explicitly configure the concurrency keyword [3][4]. When you use the concurrency keyword to define a concurrency group, you can restrict execution so that only one job or workflow run within that group is active at any time [3][1]. The default behavior when using a concurrency group is: 1. Pending jobs: Only one job or workflow run is allowed to be in a pending state at a time [3][4]. 2. Cancellation: If a new run is triggered while another run in the same group is already in progress or pending, the existing pending run is automatically canceled to make room for the new one [3][5]. You can modify this default behavior by using the queue property [4][6]. For instance, setting queue to max allows up to 100 jobs or workflow runs to wait in the concurrency group rather than being canceled [3][4]. Additionally, you can use the cancel-in-progress property to control whether currently running jobs are canceled when a new job in the same group is triggered [7]. Citations:
Define a concurrency policy for notification bursts. Each enabled 🤖 Prompt for AI AgentsSource: Linters/SAST tools |
||
| steps: | ||
| - name: Send push notification email | ||
| uses: dawidd6/action-send-mail@v3.12.0 | ||
| uses: hyperpolymath/smtp-notify-action@v0.1.0 # NOSONAR — pin authority is actions.lock (sha1-1b3b752d39a4fe4c0f28f10905e4608789d3e050) | ||
| with: | ||
| server_address: ${{ secrets.SMTP_HOST }} | ||
| server_port: ${{ secrets.SMTP_PORT }} | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
Repository: hyperpolymath/action-trust-layers
Length of output: 6586
🌐 Web query:
GitHub Actions push event branches filter branch deletion github.event.deleted head_commit null💡 Result:
In GitHub Actions, the
pushevent is triggered when a branch is deleted [1][2]. When this happens, the webhook payload reflects the deletion withdeleted: true[1][3], and thehead_commitobject is typicallynullbecause no new commit is being pushed [3]. Because thepushevent fires for both standard code pushes and branch deletions, workflows configured to run onpushwill execute on deletion events unless explicitly filtered [2][4][5]. To prevent your workflow from running during a branch deletion, you can use a conditional check in your job or step configuration [2][4][5]: if: ${{!github.event.deleted }} This conditional verifies that the push event is not a deletion, effectively bypassing the logic for deleted branches [4][5][6]. If you specifically need to handle branch deletions in a separate workflow or job, you can use thedeleteevent instead [7][2]. Note that fordeleteevents,github.event.refcontains the branch or tag name, andgithub.event.ref_typespecifies whether it was a branch or tag [8][2]. Unlike thepushevent, thedeleteevent is designed explicitly for these occurrences [7][2]. Summary of Key Differences: - Push Event: Triggered on branch creation, modification, and deletion [1][2]. Use!github.event.deletedto filter out deletions [4][6]. - Delete Event: Triggered specifically when a branch or tag is deleted [7][1]. Useif: github.event_name == 'delete'to isolate this logic [2]. - head_commit: On a deletion push event,head_commitisnull[3]. Avoid referencinggithub.event.head_commitwithout checking for its existence to prevent workflow failures [9].Citations:
Exclude branch-deletion push events.
branches: ['**']does not exclude deleted branches. A deletion push hasdeleted: trueandhead_commit: null, so this job can send an email with an emptyHead msg. Add!github.event.deletedto the job condition.🧰 Tools
🪛 zizmor (1.29.0)
[warning] 13-16: insufficient job-level concurrency limits (concurrency-limits): workflow is missing concurrency setting
(concurrency-limits)
🤖 Prompt for AI Agents