Repository navigation
Commit b689a74
chore(deps): bump hyperpolymath/smtp-notify-action from 0.3.0 to 0.5.0 in the actions group (#214)
Bumps the actions group with 1 update:
[hyperpolymath/smtp-notify-action](https://github.com/hyperpolymath/smtp-notify-action).
Updates `hyperpolymath/smtp-notify-action` from 0.3.0 to 0.5.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/hyperpolymath/smtp-notify-action/releases">hyperpolymath/smtp-notify-action's
releases</a>.</em></p>
<blockquote>
<h2>v0.5.0</h2>
<h3>Newsgroup posting, on the same binary</h3>
<p><code>protocol: nntp</code> with <code>newsgroups</code> posts one
article over implicit TLS (NNTPS, 563) or STARTTLS on the news port (RFC
4642, 119), authenticating with <code>AUTHINFO
USER</code>/<code>PASS</code>. Transport selection is fail-closed and
unchanged in shape from the SMTP path: a server that does not advertise
the upgrade is refused <em>before</em> any credential is written.</p>
<p>Refusals name their own reason, including the two 4xx codes that are
not retries — <strong>440</strong> at <code>POST</code> and
<strong>441</strong> at the article, where a class-only rule would have
advised a retry and duplicated the post. Malformed newsgroups and CR/LF
in a header-bound value are refused before the socket is opened. The
body is dot-stuffed on the wire and a <code>Message-ID</code> is
generated per run.</p>
<p>The NNTP session is a second proven contract —
<code>spec/Nntp/</code> (6 rows implicit, 8 with STARTTLS, plus the
Newsgroups grammar and <code>newsgroupsNoInjection</code>) — emitted
into the same <code>src/generated/smtp_fsm.zig</code>, so the existing
drift gate covers it. The SMTP section of that file is unchanged.</p>
<h3>The Marketplace listing can finally be published</h3>
<p>The publish form refuses a description of 125 characters or more
(measured on the parsed value, so a folded scalar does not hide it) and
reads <code>action.yml</code> from the release tag — which is why this
ships as a tag rather than a commit on <code>main</code>. The
description is now 110 characters with STARTTLS and 365 in it; the full
text lives in the README, which the listing page renders.
<code>scripts/check-action.sh</code> and the
<code>action-metadata</code> job keep the limit from regressing, with a
selftest proving 125 is refused and 124 accepted.</p>
<p><code>server_port</code> now defaults to empty, meaning the port the
protocol and transport imply: SMTP 465/587/25, NNTP 563/119.</p>
<h3>Provenance</h3>
<p>CI rebuilt both static musl binaries from this tag and verified they
hash to exactly the SHA-256 pins inside this tag's
<code>action.yml</code> before publishing. <code>SHA256SUMS</code> is
attached:</p>
<pre><code>2683da8f619dd5f310c9f6884da39e825c807c2c86a6319c19aba39b27f9c5c9
smtp-notify-x86_64-linux-musl
a58138308fb9832e1ceb551a12f1b04e591dc38ba5fd336c9acfb3f263161f29
smtp-notify-aarch64-linux-musl
</code></pre>
<p>See <code>CHANGELOG.adoc</code> for the full entry, and
<code>KNOWN-DEFECTS.adoc</code> for what is <em>not</em> proven —
notably D-015: no real news server has ever seen this code; the
end-to-end evidence is a containerised fixture.</p>
<h2>v0.4.0</h2>
<p>Static, byte-reproducible smtp-notify binaries. CI rebuilt them from
this tag and verified they hash to exactly the SHA-256 pins inside this
tag's action.yml before publishing.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/hyperpolymath/smtp-notify-action/blob/main/CHANGELOG.adoc">hyperpolymath/smtp-notify-action's
changelog</a>.</em></p>
<blockquote>
<p>== v0.5.0 — 2026-10-04</p>
<p>Newsgroup posting, and the release that can finally be listed on the
GitHub
Marketplace. The two are one release because the description fix can
only take
effect from a tag — the Marketplace validates <code>action.yml</code> at
the release's tag,
not on <code>main</code> — and a tag is what this release is for.</p>
<p>NOTE: The tag must be pushed immediately after this merge. Between
the two, the
tagged commit's <code>action.yml</code> names <code>v0.5.0</code> assets
that do not exist yet, and
<code>@main</code> inherits that window; the release workflow refuses to
publish unless the
asset URL equals the tag, so the window is a property of the release
process
rather than of this tree. If the tag lands on a later day, correct this
heading
with a follow-up commit, as was done for v0.4.0.</p>
<p>=== Added</p>
<ul>
<li><em><code>protocol</code> input (<code>smtp</code> |
<code>nntp</code>, default <code>smtp</code>)</em>, chosen explicitly
and
never inferred. <code>newsgroups</code> set while <code>protocol</code>
is <code>smtp</code> fails the step
naming the mismatch, and <code>protocol: nntp</code> without
<code>newsgroups</code> fails too,
rather than either combination being guessed at.</li>
<li><em>NNTP posting — one article per run.</em> Implicit TLS (NNTPS,
normally 563) or
<code>STARTTLS</code> on the cleartext news port (RFC 4642, normally
119), with
<code>AUTHINFO USER</code>/<code>PASS</code> (RFC 4643). The article
carries <code>From</code>, <code>Newsgroups</code>,
<code>Subject</code> (RFC 2047 for non-ASCII), <code>Date</code>, a
generated <code>Message-ID</code>,
optional <code>Content-Language</code>, <code>MIME-Version</code>,
<code>Content-Type</code> and
<code>Content-Transfer-Encoding</code>; the body is dot-stuffed on the
wire. The
STARTTLS path re-reads <code>CAPABILITIES</code> after the upgrade, as
RFC 4642 §2.2
requires, and a server that does not advertise the upgrade is refused
rather
than posted to in the clear.</li>
<li><em>A second proven contract.</em>
<code>spec/Nntp/StateMachine.idr</code> and
<code>spec/Nntp/Serialize.idr</code> hold the NNTP session tables (6
rows implicit, 8
with STARTTLS) and the Newsgroups grammar, with the same style of
properties
as the SMTP spec: deterministic coverage, termination, ordering, and
that the
upgrade is on the walked path — plus <code>newsgroupsNoInjection</code>,
the analogue of
the Content-Language theorem. Both emit into the same
<code>src/generated/smtp_fsm.zig</code>, so the existing drift gate
covers them; the
SMTP section of that file is unchanged.</li>
<li><em>Failure attribution for the news session.</em> A 201 greeting
and a 440 reply
are reported as "this server will not accept posts", 441 as
the article
itself being refused (both at <code>POST</code> and after the article,
where a class-only
rule would have advised a retry and duplicated the post), and a server
advertising <code>AUTHINFO SASL</code> alone is refused before a
credential is written.
Malformed newsgroups, CR/LF in a header-bound input, an invalid
<code>Content-Language</code> and empty credentials are refused
<em>before the socket is
opened</em>, so a typo does not read as a connection failure.</li>
<li><em><code>scripts/nntp-sink.py</code> and an <code>e2e-nntp</code>
CI job.</em> A one-shot NNTP server
fixture, the news counterpart of the Mailpit container: the job posts an
article and asserts the dialogue order, the canonicalised newsgroup
list, the
encoded-word subject, the generated <code>Message-ID</code> shape and
the dot-stuffed
line on the wire — then asserts that each refusal names its own reason
and</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/hyperpolymath/smtp-notify-action/commit/c1c9fa07992a02c1fd3d67a0dc1b08cccb852aef"><code>c1c9fa0</code></a>
feat(nntp): NNTP posting + unblock the Marketplace listing (needs tag
v0.5.0)...</li>
<li><a
href="https://github.com/hyperpolymath/smtp-notify-action/commit/7ea6d7a709e2e29172cdda5230d010ae33b70888"><code>7ea6d7a</code></a>
docs(changelog): date v0.4.0 at its actual tag push (<a
href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/26">#26</a>)</li>
<li><a
href="https://github.com/hyperpolymath/smtp-notify-action/commit/170f53ae0052c03fa4f3c677f10e3fd739848d25"><code>170f53a</code></a>
ci(secret-scan): canonical estate scanner caller, key scan (D243) (<a
href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/25">#25</a>)</li>
<li><a
href="https://github.com/hyperpolymath/smtp-notify-action/commit/9f3f89fa486ed5bf6719c0ee436e5288c4183093"><code>9f3f89f</code></a>
docs: add Signed commits section to CONTRIBUTING (<a
href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/24">#24</a>)</li>
<li><a
href="https://github.com/hyperpolymath/smtp-notify-action/commit/acd2d3dacfef7f7133cbba54227e4964857d0e0f"><code>acd2d3d</code></a>
fix: address CodeRabbit review of <a
href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/21">#21</a>
— CertificateRequest shape checks, benc...</li>
<li><a
href="https://github.com/hyperpolymath/smtp-notify-action/commit/c9b6790220c4f3886895d31da8bb2fe4fb7c0119"><code>c9b6790</code></a>
fix: CodeRabbit auto-fixes for PR <a
href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/21">#21</a>
(<a
href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/22">#22</a>)</li>
<li><a
href="https://github.com/hyperpolymath/smtp-notify-action/commit/10f080a16e0f9eeccdb5b9db2b5b76cec07ea92a"><code>10f080a</code></a>
fix/issue 6 hardening (<a
href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/21">#21</a>)</li>
<li><a
href="https://github.com/hyperpolymath/smtp-notify-action/commit/5574cdc655f5bd0ecc5f12d53ac267a6c49b4aa5"><code>5574cdc</code></a>
Resolve community health, accessibility, diagnostics, and benchmark
debt</li>
<li><a
href="https://github.com/hyperpolymath/smtp-notify-action/commit/106e28f57cd7403d0aacc744695faa00a1c73ff2"><code>106e28f</code></a>
fix(ci): reconcile the workflows with actions.lock (gh-actions-lock) (<a
href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/19">#19</a>)</li>
<li><a
href="https://github.com/hyperpolymath/smtp-notify-action/commit/2c9891021a4251c4cc3d4ddc35b49f8d26ea31ac"><code>2c98910</code></a>
fix(ci): pin third-party actions to full commit SHAs (<a
href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/18">#18</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/hyperpolymath/smtp-notify-action/compare/v0.3.0...v0.5.0">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>1 parent c9bd1ac commit b689a74
1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
44 | | - | |
| 44 | + | |
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
| |||
0 commit comments