Skip to content

Commit b689a74

Browse files
chore(deps): bump hyperpolymath/smtp-notify-action from 0.3.0 to 0.5.0 in the actions group (#214)
Bumps the actions group with 1 update: [hyperpolymath/smtp-notify-action](https://github.com/hyperpolymath/smtp-notify-action). Updates `hyperpolymath/smtp-notify-action` from 0.3.0 to 0.5.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/hyperpolymath/smtp-notify-action/releases">hyperpolymath/smtp-notify-action's releases</a>.</em></p> <blockquote> <h2>v0.5.0</h2> <h3>Newsgroup posting, on the same binary</h3> <p><code>protocol: nntp</code> with <code>newsgroups</code> posts one article over implicit TLS (NNTPS, 563) or STARTTLS on the news port (RFC 4642, 119), authenticating with <code>AUTHINFO USER</code>/<code>PASS</code>. Transport selection is fail-closed and unchanged in shape from the SMTP path: a server that does not advertise the upgrade is refused <em>before</em> any credential is written.</p> <p>Refusals name their own reason, including the two 4xx codes that are not retries — <strong>440</strong> at <code>POST</code> and <strong>441</strong> at the article, where a class-only rule would have advised a retry and duplicated the post. Malformed newsgroups and CR/LF in a header-bound value are refused before the socket is opened. The body is dot-stuffed on the wire and a <code>Message-ID</code> is generated per run.</p> <p>The NNTP session is a second proven contract — <code>spec/Nntp/</code> (6 rows implicit, 8 with STARTTLS, plus the Newsgroups grammar and <code>newsgroupsNoInjection</code>) — emitted into the same <code>src/generated/smtp_fsm.zig</code>, so the existing drift gate covers it. The SMTP section of that file is unchanged.</p> <h3>The Marketplace listing can finally be published</h3> <p>The publish form refuses a description of 125 characters or more (measured on the parsed value, so a folded scalar does not hide it) and reads <code>action.yml</code> from the release tag — which is why this ships as a tag rather than a commit on <code>main</code>. The description is now 110 characters with STARTTLS and 365 in it; the full text lives in the README, which the listing page renders. <code>scripts/check-action.sh</code> and the <code>action-metadata</code> job keep the limit from regressing, with a selftest proving 125 is refused and 124 accepted.</p> <p><code>server_port</code> now defaults to empty, meaning the port the protocol and transport imply: SMTP 465/587/25, NNTP 563/119.</p> <h3>Provenance</h3> <p>CI rebuilt both static musl binaries from this tag and verified they hash to exactly the SHA-256 pins inside this tag's <code>action.yml</code> before publishing. <code>SHA256SUMS</code> is attached:</p> <pre><code>2683da8f619dd5f310c9f6884da39e825c807c2c86a6319c19aba39b27f9c5c9 smtp-notify-x86_64-linux-musl a58138308fb9832e1ceb551a12f1b04e591dc38ba5fd336c9acfb3f263161f29 smtp-notify-aarch64-linux-musl </code></pre> <p>See <code>CHANGELOG.adoc</code> for the full entry, and <code>KNOWN-DEFECTS.adoc</code> for what is <em>not</em> proven — notably D-015: no real news server has ever seen this code; the end-to-end evidence is a containerised fixture.</p> <h2>v0.4.0</h2> <p>Static, byte-reproducible smtp-notify binaries. CI rebuilt them from this tag and verified they hash to exactly the SHA-256 pins inside this tag's action.yml before publishing.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/hyperpolymath/smtp-notify-action/blob/main/CHANGELOG.adoc">hyperpolymath/smtp-notify-action's changelog</a>.</em></p> <blockquote> <p>== v0.5.0 — 2026-10-04</p> <p>Newsgroup posting, and the release that can finally be listed on the GitHub Marketplace. The two are one release because the description fix can only take effect from a tag — the Marketplace validates <code>action.yml</code> at the release's tag, not on <code>main</code> — and a tag is what this release is for.</p> <p>NOTE: The tag must be pushed immediately after this merge. Between the two, the tagged commit's <code>action.yml</code> names <code>v0.5.0</code> assets that do not exist yet, and <code>@main</code> inherits that window; the release workflow refuses to publish unless the asset URL equals the tag, so the window is a property of the release process rather than of this tree. If the tag lands on a later day, correct this heading with a follow-up commit, as was done for v0.4.0.</p> <p>=== Added</p> <ul> <li><em><code>protocol</code> input (<code>smtp</code> | <code>nntp</code>, default <code>smtp</code>)</em>, chosen explicitly and never inferred. <code>newsgroups</code> set while <code>protocol</code> is <code>smtp</code> fails the step naming the mismatch, and <code>protocol: nntp</code> without <code>newsgroups</code> fails too, rather than either combination being guessed at.</li> <li><em>NNTP posting — one article per run.</em> Implicit TLS (NNTPS, normally 563) or <code>STARTTLS</code> on the cleartext news port (RFC 4642, normally 119), with <code>AUTHINFO USER</code>/<code>PASS</code> (RFC 4643). The article carries <code>From</code>, <code>Newsgroups</code>, <code>Subject</code> (RFC 2047 for non-ASCII), <code>Date</code>, a generated <code>Message-ID</code>, optional <code>Content-Language</code>, <code>MIME-Version</code>, <code>Content-Type</code> and <code>Content-Transfer-Encoding</code>; the body is dot-stuffed on the wire. The STARTTLS path re-reads <code>CAPABILITIES</code> after the upgrade, as RFC 4642 §2.2 requires, and a server that does not advertise the upgrade is refused rather than posted to in the clear.</li> <li><em>A second proven contract.</em> <code>spec/Nntp/StateMachine.idr</code> and <code>spec/Nntp/Serialize.idr</code> hold the NNTP session tables (6 rows implicit, 8 with STARTTLS) and the Newsgroups grammar, with the same style of properties as the SMTP spec: deterministic coverage, termination, ordering, and that the upgrade is on the walked path — plus <code>newsgroupsNoInjection</code>, the analogue of the Content-Language theorem. Both emit into the same <code>src/generated/smtp_fsm.zig</code>, so the existing drift gate covers them; the SMTP section of that file is unchanged.</li> <li><em>Failure attribution for the news session.</em> A 201 greeting and a 440 reply are reported as &quot;this server will not accept posts&quot;, 441 as the article itself being refused (both at <code>POST</code> and after the article, where a class-only rule would have advised a retry and duplicated the post), and a server advertising <code>AUTHINFO SASL</code> alone is refused before a credential is written. Malformed newsgroups, CR/LF in a header-bound input, an invalid <code>Content-Language</code> and empty credentials are refused <em>before the socket is opened</em>, so a typo does not read as a connection failure.</li> <li><em><code>scripts/nntp-sink.py</code> and an <code>e2e-nntp</code> CI job.</em> A one-shot NNTP server fixture, the news counterpart of the Mailpit container: the job posts an article and asserts the dialogue order, the canonicalised newsgroup list, the encoded-word subject, the generated <code>Message-ID</code> shape and the dot-stuffed line on the wire — then asserts that each refusal names its own reason and</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/hyperpolymath/smtp-notify-action/commit/c1c9fa07992a02c1fd3d67a0dc1b08cccb852aef"><code>c1c9fa0</code></a> feat(nntp): NNTP posting + unblock the Marketplace listing (needs tag v0.5.0)...</li> <li><a href="https://github.com/hyperpolymath/smtp-notify-action/commit/7ea6d7a709e2e29172cdda5230d010ae33b70888"><code>7ea6d7a</code></a> docs(changelog): date v0.4.0 at its actual tag push (<a href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/26">#26</a>)</li> <li><a href="https://github.com/hyperpolymath/smtp-notify-action/commit/170f53ae0052c03fa4f3c677f10e3fd739848d25"><code>170f53a</code></a> ci(secret-scan): canonical estate scanner caller, key scan (D243) (<a href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/25">#25</a>)</li> <li><a href="https://github.com/hyperpolymath/smtp-notify-action/commit/9f3f89fa486ed5bf6719c0ee436e5288c4183093"><code>9f3f89f</code></a> docs: add Signed commits section to CONTRIBUTING (<a href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/24">#24</a>)</li> <li><a href="https://github.com/hyperpolymath/smtp-notify-action/commit/acd2d3dacfef7f7133cbba54227e4964857d0e0f"><code>acd2d3d</code></a> fix: address CodeRabbit review of <a href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/21">#21</a> — CertificateRequest shape checks, benc...</li> <li><a href="https://github.com/hyperpolymath/smtp-notify-action/commit/c9b6790220c4f3886895d31da8bb2fe4fb7c0119"><code>c9b6790</code></a> fix: CodeRabbit auto-fixes for PR <a href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/21">#21</a> (<a href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/22">#22</a>)</li> <li><a href="https://github.com/hyperpolymath/smtp-notify-action/commit/10f080a16e0f9eeccdb5b9db2b5b76cec07ea92a"><code>10f080a</code></a> fix/issue 6 hardening (<a href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/21">#21</a>)</li> <li><a href="https://github.com/hyperpolymath/smtp-notify-action/commit/5574cdc655f5bd0ecc5f12d53ac267a6c49b4aa5"><code>5574cdc</code></a> Resolve community health, accessibility, diagnostics, and benchmark debt</li> <li><a href="https://github.com/hyperpolymath/smtp-notify-action/commit/106e28f57cd7403d0aacc744695faa00a1c73ff2"><code>106e28f</code></a> fix(ci): reconcile the workflows with actions.lock (gh-actions-lock) (<a href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/19">#19</a>)</li> <li><a href="https://github.com/hyperpolymath/smtp-notify-action/commit/2c9891021a4251c4cc3d4ddc35b49f8d26ea31ac"><code>2c98910</code></a> fix(ci): pin third-party actions to full commit SHAs (<a href="https://redirect.github.com/hyperpolymath/smtp-notify-action/issues/18">#18</a>)</li> <li>Additional commits viewable in <a href="https://github.com/hyperpolymath/smtp-notify-action/compare/v0.3.0...v0.5.0">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=hyperpolymath/smtp-notify-action&package-manager=github_actions&previous-version=0.3.0&new-version=0.5.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
1 parent c9bd1ac commit b689a74

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

‎.github/workflows/push-email-notify.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ jobs:
4141
timeout-minutes: 5
4242
steps:
4343
- name: Send push notification email
44-
uses: hyperpolymath/smtp-notify-action@v0.3.0
44+
uses: hyperpolymath/smtp-notify-action@v0.5.0
4545
with:
4646
server_address: ${{ secrets.SMTP_HOST }}
4747
server_port: ${{ secrets.SMTP_PORT }}

0 commit comments

Comments
 (0)