|
1 | 1 | # SPDX-License-Identifier: MPL-2.0 |
2 | 2 | # This workflow is managed by gh actions-lock. |
3 | | -# This workflow is managed by gh actions-lock. |
4 | 3 | # Dormant push-email notification. ARMED by setting the repo variable |
5 | 4 | # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; |
6 | 5 | # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by |
7 | 6 | # new repos from the template; placed on existing repos by the farm sweep. |
| 7 | +# |
| 8 | +# Re-landed after the 2026-07-20 notification-storm freeze (removed in |
| 9 | +# 09f94c5), now on hyperpolymath/smtp-notify-action: Node-free, the SMTP |
| 10 | +# session is Idris2-specified and machine-checked, the binary is Zig-built, |
| 11 | +# byte-reproducible, and SHA-256-pinned inside the action itself. |
8 | 12 | name: Push email notification |
9 | 13 | on: |
10 | | - push: {} |
| 14 | + push: |
| 15 | + # Branch pushes only: tag and deletion payloads mislabel Branch:/head_commit. |
| 16 | + branches: ['**'] |
| 17 | +concurrency: |
| 18 | + # Deliberately per-RUN, so no run is ever queued behind another and none is |
| 19 | + # ever cancelled. Do NOT "tidy" this into a shared group such as |
| 20 | + # ${{ github.workflow }}-${{ github.ref }}. GitHub's workflow-syntax docs: |
| 21 | + # "By default, any existing pending job or workflow in the same concurrency |
| 22 | + # group will be canceled and the new queued job or workflow will take its |
| 23 | + # place." That happens regardless of cancel-in-progress, which governs only |
| 24 | + # the RUNNING job. On this workflow it silently loses a notification email, |
| 25 | + # with no error anywhere. Every run here reports a DISTINCT commit, so there |
| 26 | + # is no redundant work for a concurrency limit to remove. |
| 27 | + # The docs also offer `queue: max` (up to 100 pending); not used, because 100 |
| 28 | + # is still a cap whereas a per-run group needs none. |
| 29 | + # Verified with zizmor 1.30.0: deleting this block raises concurrency-limits; |
| 30 | + # this form silences it exactly as a shared group would. |
| 31 | + group: push-email-${{ github.run_id }} |
| 32 | + cancel-in-progress: false |
11 | 33 | permissions: |
12 | | - actions: read |
13 | 34 | contents: read |
14 | 35 | jobs: |
15 | 36 | notify: |
16 | 37 | name: Email on push |
17 | 38 | if: ${{ vars.PUSH_EMAIL_ENABLED == 'true' }} |
18 | 39 | runs-on: ubuntu-latest |
19 | | - timeout-minutes: 10 |
| 40 | + timeout-minutes: 5 |
20 | 41 | steps: |
21 | 42 | - name: Send push notification email |
22 | | - uses: dawidd6/action-send-mail@v3.12.0 |
| 43 | + uses: hyperpolymath/smtp-notify-action@v0.2.0 # NOSONAR — pin authority is actions.lock (sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7) |
23 | 44 | with: |
24 | 45 | server_address: ${{ secrets.SMTP_HOST }} |
25 | 46 | server_port: ${{ secrets.SMTP_PORT }} |
|
0 commit comments