Skip to content

Commit 657ecfe

Browse files
chore(ci): repoint push-email-notify to smtp-notify-action (#130)
Replaces `dawidd6/action-send-mail` with `hyperpolymath/smtp-notify-action` v0.2.0 (tag commit `ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7`), per the 2026-09-02 ruling (standards spec §5.5/§9, PR hyperpolymath/standards#725). The whole file is replaced with the `rsr-template-repo` canonical, which — besides the `uses:` line — restricts the trigger to branch pushes (tag and deletion payloads mislabel `Branch:`/`head_commit`), sets `timeout-minutes: 5`, carries a deliberately per-run `concurrency` group, and grants only `contents: read`. **How many of those are actual changes here depends on how far this repo's copy had drifted — read the diff, not this list.** Dormant gating on `vars.PUSH_EMAIL_ENABLED == 'true'` is unchanged. Line 1 SPDX header kept as it was. Engine: `.git-private-farm/scripts/smtp-notify-sweep.sh`. Verification for this repo: `regime=lock pristine=valid post=valid changed=.github/workflows/actions.lock,.github/workflows/push-email-notify.yml, sig=G d38066d canon=543fc1474b54 base=main` (`pristine`/`post` = `gh actions-lock --no-fix` validity before/after; `repair` = the lock was already invalid before this change and is valid after it.) 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
1 parent b0b2cd3 commit 657ecfe

2 files changed

Lines changed: 39 additions & 16 deletions

File tree

‎.github/workflows/actions.lock‎

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -3,13 +3,6 @@
33
# Docs: https://gh.io/actions-lockfile
44
version: 'v0.0.2'
55
workflows:
6-
'.github/workflows/governance.yml': []
7-
'.github/workflows/hypatia-scan.yml': []
8-
'.github/workflows/label-triage.yml': []
9-
'.github/workflows/labels.yml': []
10-
'.github/workflows/mirror.yml': []
11-
'.github/workflows/scorecard.yml': []
12-
'.github/workflows/secret-scanner.yml': []
136
'.github/workflows/boj-build.yml':
147
- 'actions/checkout@v7.0.1'
158
'.github/workflows/casket-pages.yml':
@@ -26,10 +19,17 @@ workflows:
2619
- 'actions/checkout@v7.0.1'
2720
- 'hyperpolymath/a2ml-ecosystem@main'
2821
- 'hyperpolymath/k9-ecosystem@main'
22+
'.github/workflows/governance.yml': []
23+
'.github/workflows/hypatia-scan.yml': []
2924
'.github/workflows/instant-sync.yml':
3025
- 'peter-evans/repository-dispatch@v4.0.1'
26+
'.github/workflows/label-triage.yml': []
27+
'.github/workflows/labels.yml': []
28+
'.github/workflows/mirror.yml': []
3129
'.github/workflows/push-email-notify.yml':
32-
- 'dawidd6/action-send-mail@v3.12.0'
30+
- 'hyperpolymath/smtp-notify-action@v0.2.0'
31+
'.github/workflows/scorecard.yml': []
32+
'.github/workflows/secret-scanner.yml': []
3333
dependencies:
3434
'actions/cache@v6.1.0':
3535
ref: 'v6.1.0'
@@ -63,11 +63,6 @@ dependencies:
6363
repo_id: 496012378
6464
uses:
6565
- 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f'
66-
'dawidd6/action-send-mail@v3.12.0':
67-
ref: 'v3.12.0'
68-
commit: 'sha1-94de994a9f6fffee200243214e17002e2920bb59'
69-
owner_id: 9713907
70-
repo_id: 222439721
7166
'github/codeql-action@v4.37.7':
7267
ref: 'v4.37.7'
7368
commit: 'sha1-ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd'
@@ -88,6 +83,11 @@ dependencies:
8883
commit: 'sha1-921f599d0b5bc6de4627338b014059ab6bcea5b8'
8984
owner_id: 6759885
9085
repo_id: 1275650185
86+
'hyperpolymath/smtp-notify-action@v0.2.0':
87+
ref: 'v0.2.0'
88+
commit: 'sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7'
89+
owner_id: 6759885
90+
repo_id: 1352485172
9191
'peter-evans/repository-dispatch@v4.0.1':
9292
ref: 'v4.0.1'
9393
commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697'

‎.github/workflows/push-email-notify.yml‎

Lines changed: 26 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,23 +1,46 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3-
# This workflow is managed by gh actions-lock.
43
# Dormant push-email notification. ARMED by setting the repo variable
54
# PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled;
65
# sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by
76
# new repos from the template; placed on existing repos by the farm sweep.
7+
#
8+
# Re-landed after the 2026-07-20 notification-storm freeze (removed in
9+
# 09f94c5), now on hyperpolymath/smtp-notify-action: Node-free, the SMTP
10+
# session is Idris2-specified and machine-checked, the binary is Zig-built,
11+
# byte-reproducible, and SHA-256-pinned inside the action itself.
812
name: Push email notification
913
on:
10-
push: {}
14+
push:
15+
# Branch pushes only: tag and deletion payloads mislabel Branch:/head_commit.
16+
branches: ['**']
17+
concurrency:
18+
# Deliberately per-RUN, so no run is ever queued behind another and none is
19+
# ever cancelled. Do NOT "tidy" this into a shared group such as
20+
# ${{ github.workflow }}-${{ github.ref }}. GitHub's workflow-syntax docs:
21+
# "By default, any existing pending job or workflow in the same concurrency
22+
# group will be canceled and the new queued job or workflow will take its
23+
# place." That happens regardless of cancel-in-progress, which governs only
24+
# the RUNNING job. On this workflow it silently loses a notification email,
25+
# with no error anywhere. Every run here reports a DISTINCT commit, so there
26+
# is no redundant work for a concurrency limit to remove.
27+
# The docs also offer `queue: max` (up to 100 pending); not used, because 100
28+
# is still a cap whereas a per-run group needs none.
29+
# Verified with zizmor 1.30.0: deleting this block raises concurrency-limits;
30+
# this form silences it exactly as a shared group would.
31+
group: push-email-${{ github.run_id }}
32+
cancel-in-progress: false
1133
permissions:
1234
contents: read
1335
jobs:
1436
notify:
1537
name: Email on push
1638
if: ${{ vars.PUSH_EMAIL_ENABLED == 'true' }}
1739
runs-on: ubuntu-latest
40+
timeout-minutes: 5
1841
steps:
1942
- name: Send push notification email
20-
uses: dawidd6/action-send-mail@v3.12.0
43+
uses: hyperpolymath/smtp-notify-action@v0.2.0 # NOSONAR — pin authority is actions.lock (sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7)
2144
with:
2245
server_address: ${{ secrets.SMTP_HOST }}
2346
server_port: ${{ secrets.SMTP_PORT }}

0 commit comments

Comments
 (0)