-
-
Notifications
You must be signed in to change notification settings - Fork 0
chore(ci): repoint push-email-notify to smtp-notify-action #74
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -3,20 +3,27 @@ | |
| # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; | ||
| # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by | ||
| # new repos from the template; placed on existing repos by the farm sweep. | ||
| # | ||
| # Re-landed after the 2026-07-20 notification-storm freeze (removed in | ||
| # 09f94c5), now on hyperpolymath/smtp-notify-action: Node-free, the SMTP | ||
| # session is Idris2-specified and machine-checked, the binary is Zig-built, | ||
| # byte-reproducible, and SHA-256-pinned inside the action itself. | ||
| name: Push email notification | ||
| on: | ||
| push: {} | ||
| push: | ||
| # Branch pushes only: tag and deletion payloads mislabel Branch:/head_commit. | ||
| branches: ['**'] | ||
| permissions: | ||
| actions: read | ||
| contents: read | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win Remove the unnecessary repository permission. This workflow only invokes the SMTP action. It does not check out repository contents or call GitHub APIs. Proposed permission reduction-permissions:
- contents: read
+permissions: {}🤖 Prompt for AI AgentsSource: MCP tools |
||
| jobs: | ||
| notify: | ||
| name: Email on push | ||
| if: ${{ vars.PUSH_EMAIL_ENABLED == 'true' }} | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 5 | ||
| steps: | ||
| - name: Send push notification email | ||
| uses: dawidd6/action-send-mail@6e502825a508b867ab2954ad6343b68787624c01 # pinned | ||
| uses: hyperpolymath/smtp-notify-action@1b3b752d39a4fe4c0f28f10905e4608789d3e050 # v0.1.0 | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🗄️ Data Integrity & Integration | 🔵 Trivial 🔎 Supported by static analysis🏁 Script executed: #!/bin/bash
set -e
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/push-email-notify.yml
printf '%s\n' '--- relevant secret and port references ---'
rg -n --hidden -S 'SMTP_PORT|smtp-notify-action|SMTP_HOST|SMTP_USER|SMTP_PASSWORD' .github README.md 2>/dev/null || trueRepository: hyperpolymath/aerie Length of output: 3069 🌐 Web query:
💡 Result: The term smtp-notify-action does not refer to a unique, standalone software project, but rather identifies a pattern of workflow automation used within the hyperpolymath GitHub organization [1][2][3][4][5]. Repositories in this organization typically contain a.github/workflows/push-email-notify.yml file that utilizes the third-party GitHub Action dawidd6/action-send-mail to send notifications upon code pushes [1][2][3][4][5]. Regarding the technical parameters requested: - secure: When using dawidd6/action-send-mail (often utilized in these workflows), the secure parameter is typically set to true [1][2][3][4][5]. In the context of SMTP, this generally indicates that the connection should use TLS/SSL [6][7][8]. - STARTTLS vs. Direct TLS: The behavior of the secure parameter often depends on the SMTP port chosen [8]. For example, a secure: true setting with port 465 typically initiates a direct TLS connection, whereas port 587 is commonly used with STARTTLS [8]. - SMTP_PORT: This value is retrieved from GitHub Secrets (secrets.SMTP_PORT) in the hyperpolymath workflows [1][2][3][4][5]. The specific port number is not hardcoded in the repository workflows themselves, as it is intended to be provided by the organization's secret configuration [1][2][3][4][5]. The specific hash 1b3b752d39a4fe4c0f28f10905e4608789d3e050 corresponds to a specific commit version of the dawidd6/action-send-mail action used in the hyperpolymath/volumod repository [1]. Because this is a pinned version of a third-party action, refer to the documentation for dawidd6/action-send-mail for precise implementation details regarding how it handles the secure flag and STARTTLS handshakes [1]. Citations:
🏁 Script executed: #!/bin/bash
set -e
base='https://raw.githubusercontent.com/hyperpolymath/smtp-notify-action/1b3b752d39a4fe4c0f28f10905e4608789d3e050'
printf '%s\n' '--- action.yml ---'
curl -fsSL "$base/action.yml"
printf '%s\n' '--- repository files at the pinned revision ---'
curl -fsSL "https://api.github.com/repos/hyperpolymath/smtp-notify-action/git/trees/1b3b752d39a4fe4c0f28f10905e4608789d3e050?recursive=1" |
jq -r '.tree[]?.path' | sed -n '1,120p'Repository: hyperpolymath/aerie Length of output: 4353 🏁 Script executed: #!/bin/bash
set -e
base='https://raw.githubusercontent.com/hyperpolymath/smtp-notify-action/1b3b752d39a4fe4c0f28f10905e4608789d3e050'
printf '%s\n' '--- README transport configuration ---'
curl -fsSL "$base/README.adoc" | rg -n -A8 -B5 'SMTP_PORT|SMTP_SECURE|STARTTLS|implicit|465|587'
printf '%s\n' '--- source transport configuration ---'
curl -fsSL "$base/src/main.zig" | rg -n -A12 -B8 'SMTP_PORT|SMTP_SECURE|parse|secure'
curl -fsSL "$base/src/smtp.zig" | rg -n -A18 -B8 'tls|connect|SMTP_PORT|starttls|STARTTLS'Repository: hyperpolymath/aerie Length of output: 10251 Use an implicit-TLS SMTP endpoint. The pinned action passes 🤖 Prompt for AI AgentsSource: MCP tools |
||
| with: | ||
| server_address: ${{ secrets.SMTP_HOST }} | ||
| server_port: ${{ secrets.SMTP_PORT }} | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🚀 Performance & Scalability | 🔵 Trivial
🔎 Supported by static analysis
🏁 Script executed:
Repository: hyperpolymath/aerie
Length of output: 44812
🌐 Web query:
GitHub Actions workflow concurrency default multiple jobs runs can run concurrently official documentation💡 Result:
By default, GitHub Actions allows multiple jobs within the same workflow, multiple workflow runs within the same repository, and multiple workflow runs across an account to execute concurrently [1][2]. There is no restriction on concurrent execution unless you explicitly configure it [1][2]. To restrict concurrency, you use the
concurrencykeyword [1][3]. When you define a concurrency group, GitHub Actions ensures that only one job or workflow run within that group is active at a time [2][4]. Key behaviors when using theconcurrencykeyword include: 1. Pending State: If a job or workflow is queued while another in the same concurrency group is already running, the new job or workflow will enter apendingstate [2][3]. 2. Cancellation: By default, if a new job or workflow is triggered for a group that already has apendingrun, the existingpendingrun is canceled and replaced by the new one [2][4]. 3. Queuing (Opt-in): You can change this behavior by settingqueue: maxwithin your concurrency configuration. This allows up to 100 jobs or workflows to wait in a queue to execute sequentially instead of being canceled [2][4]. 4. Scope: Concurrency can be applied at the workflow level (top of the YAML file) or the job level (inside a specific job) [5]. In summary, concurrency is effectively "disabled" by default (allowing unlimited simultaneous runs), and you must explicitly define a concurrency group if you wish to limit or serialize the execution of your jobs or workflows [1][2].Citations:
Define a policy for notification bursts.
With
PUSH_EMAIL_ENABLEDset totrue,branches: ['**']starts thenotifyjob for each branch push. Without aconcurrencypolicy, these runs can execute concurrently;timeout-minutes: 5limits each job but does not rate-limit email delivery. If every push does not require an email, add explicit concurrency or rate control.🧰 Tools
🪛 zizmor (1.29.0)
[warning] 12-15: insufficient job-level concurrency limits (concurrency-limits): workflow is missing concurrency setting
(concurrency-limits)
🤖 Prompt for AI Agents
Sources: MCP tools, Linters/SAST tools
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
sed -n '1,120p' .github/workflows/push-email-notify.ymlRepository: hyperpolymath/aerie
Length of output: 1973
🌐 Web query:
GitHub Actions push event deleted branch branches filter branches ['**'] head_commit null💡 Result:
In GitHub Actions, the push event is triggered not only when commits are pushed but also when a branch is deleted [1][2][3]. When a branch is deleted, the push event payload includes
"deleted": true, and thehead_commitfield is set tonullbecause there is no head commit remaining on that deleted reference [1][2][4]. If your workflow uses a branch filter (such asbranches: ['']), it will still trigger on a branch deletion if that branch matches the filter criteria, because the deletion event is technically a type of push event [5][1][3]. Sincehead_commitisnullin this scenario, any workflow steps or expressions that attempt to accessgithub.event.head_commitwill fail or cause errors (e.g.,TypeError: Cannot access member...) [4][6]. To handle this behavior, you can use the following methods: 1. Conditional Job Execution: Use anifcondition to skip jobs when a branch is deleted [3]. if: ${{!github.event.deleted }} 2. Filter at the Step Level: Use anifcondition on specific steps that depend on the commit object [7]. if: ${{ github.event.head_commit!= null }} 3. Use thedeleteevent: If you specifically need to handle branch deletions, use thedeleteevent trigger instead of overloading thepushevent [1][3]. This event provides specific information about the deleted ref (e.g.,github.event.ref) without the ambiguity of thepushevent payload [3]. Note that usingbranches: ['']includes all branches, so the workflow will respond to deletions of any branch matching your configuration [8][9]. If you intend to ignore deletions entirely, checkinggithub.event.deletedin a job-levelifconditional is the standard approach [3].Citations:
Exclude branch-deletion push events.
branches: ['**']matches deleted branch refs, sonotifyruns whenPUSH_EMAIL_ENABLEDis'true'even thoughgithub.event.head_commitisnull. Add!github.event.deletedto the job condition.🧰 Tools
🪛 zizmor (1.29.0)
[warning] 12-15: insufficient job-level concurrency limits (concurrency-limits): workflow is missing concurrency setting
(concurrency-limits)
🤖 Prompt for AI Agents
Source: MCP tools